PT-2025-41490 · Unknown · Bigbluebutton

Brocked200

+1

·

Published

2025-10-09

·

Updated

2025-10-20

·

CVE-2025-61602

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 3.0.13
Description BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) condition exists in versions prior to 3.0.13. An authenticated user can disrupt chat functionality for all meeting participants by sending a malformed reactionEmojiId within the chatSendMessageReaction GraphQL mutation. The vulnerability resides in the handling of the reactionEmojiId parameter.
Recommendations Update to version 3.0.13 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61602
GHSA-45J2-M26C-3PCM

Affected Products

Bigbluebutton