Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-43797
HistoryOct 30, 2023 - 11:15 p.m.

Cross site scripting

2023-10-3023:15:00
PRIOn knowledge base
www.prio-n.com
2
bigbluebutton
virtual classroom
cross-site scripting
vulnerability
guest lobby
unsanitized messages
text sanitizing
nvd

0.001 Low

EPSS

Percentile

21.3%

BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.

0.001 Low

EPSS

Percentile

21.3%

Related for PRION:CVE-2023-43797