CVEs Blog | G5 Cyber Security

CVE-2020-25820 – BigBlueButton before 2.2.27 allows remote authenticated users to read loc

BigBlueButton before 2.2.27 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25820

Reference (s):

Exit mobile version