Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when notification about the attacker leaving room is displayed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BigBlueButton 跨站脚本漏洞
Vulnerability Description
BigBlueButton是BigBlueButton社区的一套开源的Web会议系统。 BigBlueButton v2.4.7及之前版本存在安全漏洞,攻击者利用该漏洞可以在用户名中注入 JavaScript 有效负载,每次攻击者向受害者发送私人消息或显示有关攻击者离开房间的通知时,有效载荷都会在受害者的浏览器中执行。
CVSS Information
N/A
Vulnerability Type
N/A