ZeroHour

CVE-2022-26497

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p56
Published
()
Modified
Description

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

Vendors
bigbluebutton
Products
greenlight
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.