Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43wq-r34m-56ch

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.

EPSS

Процентиль: 55%
0.00328
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.

EPSS

Процентиль: 55%
0.00328
Низкий

Дефекты

CWE-79