Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vxc-xx4f-gp2p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

EPSS

Процентиль: 52%
0.00289
Низкий

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

EPSS

Процентиль: 52%
0.00289
Низкий

Дефекты

CWE-862