CVE-2020-28954
19.11.2020, 22:15
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.Enginsight
Vendor | Product | Version |
---|---|---|
bigbluebutton | bigbluebutton | 𝑥 < 2.2.29 |
𝑥
= Vulnerable software versions
References