CVE-2020-26163
30.09.2020, 18:15
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.Enginsight
Vendor | Product | Version |
---|---|---|
bigbluebutton | greenlight | 𝑥 < 2.5.6 |
𝑥
= Vulnerable software versions
References