Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-47230 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds. |
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-06T20:12:00.883Z
Reserved: 2023-09-14T16:13:33.306Z
Link: CVE-2023-42803
Updated: 2024-08-02T19:30:24.327Z
Status : Modified
Published: 2023-10-30T19:15:07.963
Modified: 2026-06-17T06:24:32.810
Link: CVE-2023-42803
No data.
OpenCVE Enrichment
No data.
-
CWE-434
Unrestricted Upload of File with Dangerous Type
EUVD