CVE-2023-43797
Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML.
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- bigbluebutton/bigbluebutton
- Source
- security-advisories@github.com
References
- https://github.com/bigbluebutton/bigbluebutton/commit/304bc851a00558f99a908880f4ac44234a074c9dPatch, Third Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/pull/18392Third Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6wg-q866-h73xThird Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/commit/304bc851a00558f99a908880f4ac44234a074c9dPatch, Third Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/pull/18392Third Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6wg-q866-h73xThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.