CVE-2020-25820
21.10.2020, 13:15
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
Vendor | Product | Version |
---|---|---|
bigbluebutton | bigbluebutton | 𝑥 < 2.2.27 |
𝑥
= Vulnerable software versions
References