PT-2025-41489 · Unknown · Bigbluebutton
Brocked200
+1
·
Published
2025-10-09
·
Updated
2025-10-20
·
CVE-2025-61601
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions prior to 3.0.13
Description
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) issue exists that allows any authenticated user to freeze or crash the server by abusing the polling feature's
Choices response type. An attacker can submit a malicious payload with a massive array in the answerIds field, causing the current meeting – and potentially all meetings on the server – to become unresponsive. The attack leverages the answerIds field to overwhelm the server's processing capabilities.Recommendations
Update to version 3.0.13 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton