BigBlueButton是BigBlueButton社区的一套开源的Web会议系统。 BigBlueButton v2.4.7及之前版本存在安全漏洞,攻击者利用该漏洞可以在用户名中注入 JavaScript 有效负载,每次攻击者向受害者发送私人消息或显示有关攻击者离开房间的通知时,有效载荷都会在受害者的浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-21231 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-32996 | RootInteractive 安全漏洞 | |
| CVE-2022-34065 | rondolu-yt-concate 安全漏洞 | |
| CVE-2022-34066 | Texercise 安全漏洞 | |
| CVE-2022-34064 | Zibal 安全漏洞 | |
| CVE-2022-33002 | KGExplore 安全漏洞 | |
| CVE-2022-33001 | AAmiles 安全漏洞 | |
| CVE-2022-33000 | AAmiles 安全漏洞 | |
| CVE-2022-32999 | PyPI cloudlabeling 安全漏洞 | |
| CVE-2022-32998 | cryptoasset-data-downloader 安全漏洞 | |
| CVE-2022-32997 | RootInteractive 安全漏洞 | |
| CVE-2022-33003 | watools 安全漏洞 | |
| CVE-2022-33910 | MantisBT 跨站脚本漏洞 | |
| CVE-2022-29578 | Meridian Cooperative Meridian 授权问题漏洞 | |
| CVE-2022-30028 | Dradis 竞争条件问题漏洞 | |
| CVE-2021-39409 | Online Student Rate System 安全漏洞 | |
| CVE-2021-39408 | Online Student Rate System 跨站脚本漏洞 | |
| CVE-2021-42056 | Thales Safenet Authentication Client 后置链接漏洞 | |
| CVE-2021-40893 | validate-data 安全漏洞 | |
| CVE-2022-29330 | VitalPBX 安全特征问题漏洞 |
Showing top 20 of 69 CVEs. View all on vendor page → →
No comments yet