← Späť na vyhľadávanie CVE

CVE-2026-46353

BigBlueButton

Popis

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21.

CVSS 8.1EPSS 0.266%Riziko 0.83
Zobraziť zdroj
Zverejnené
2026-07-16 19:16:46
Dotknuté verzie
<3.0.21
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N