Skip to content

Stored XSS at Guest Lobby

Moderate
antobinary published GHSA-v6wg-q866-h73x Oct 30, 2023

Package

No package listed

Affected versions

<2.6.11, <2.7.0-beta.3

Patched versions

2.6.11, 2.7.0-beta.3

Description

Impact

Guest Lobby was vulnerable to XSS when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML.

Patches

Text sanitizing was added for lobby messages.

Patch on BigBlueButton 2.6.11: 304bc85
Patch on BigBlueButton 2.7.0-beta.3: #18392 (carried forward the fix from 2.6.11)

Workarounds

There are no workarounds. We recommend upgrading to a patched version of BigBlueButton.

Credits

devme4f from VNPT-VCI who contacted us via huntr.dev and responsibly disclosed this vulnerability.

Severity

Moderate
6.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVE ID

CVE-2023-43797

Weaknesses