PT-2020-13043 · Bigbluebutton · Bigbluebutton

Published

2020-04-23

·

Updated

2022-10-05

·

CVE-2020-12112

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 2.2.5
Description The issue allows remote attackers to obtain sensitive files via Local File Inclusion.
Recommendations For versions prior to 2.2.5, update to version 2.2.5 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-12112

Affected Products

Bigbluebutton