Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3cv-3c36-h8j2

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

EPSS

Процентиль: 49%
0.00258
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

EPSS

Процентиль: 49%
0.00258
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79