Vulnerabilities > Bigbluebutton > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2020-27602 Injection vulnerability in Bigbluebutton
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
network
low complexity
bigbluebutton CWE-74
critical
9.8
2020-10-21 CVE-2020-27605 Unspecified vulnerability in Bigbluebutton
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
network
low complexity
bigbluebutton
critical
9.8
2020-04-29 CVE-2020-12443 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence.
network
low complexity
bigbluebutton CWE-22
critical
9.8