Skip to content

Unrestricted File Upload

Moderate
antobinary published GHSA-w98f-6x8w-xhjc Oct 30, 2023

Package

No package listed

Affected versions

< 2.6.0

Patched versions

2.6.0

Description

Impact

BigBlueButton 2.5 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures.

Patches

Patch on BigBlueButton 2.6.0-beta.2: #15990

Workarounds

There are no workarounds. We recommend upgrading to a patched version of BigBlueButton.

References

Credits

Abdulmohsen Alotaibi who contacted us via huntr.dev and responsibly disclosed this vulnerability.

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE ID

CVE-2023-42803

Weaknesses

No CWEs