BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
References
Configurations
History
No history.
Information
Published : 2020-10-21 13:15
Updated : 2024-11-21 05:18
NVD link : CVE-2020-25820
Mitre link : CVE-2020-25820
CVE.ORG link : CVE-2020-25820
JSON object : View
Products Affected
bigbluebutton
- bigbluebutton
CWE
CWE-918
Server-Side Request Forgery (SSRF)