PT-2025-44055 · Unknown+1 · Bigbluebutton+1

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-62781

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PILOS versions prior to 4.8.0
Description PILOS, a frontend for BigBlueButton, contains a flaw where changing a local user’s password does not invalidate existing session tokens, except for the current session. An attacker who previously obtained a valid session token can maintain access even after the user changes their password. The issue occurs because the current session’s token remains valid after the password change. This allows continued unauthorized access as the user.
Recommendations Update to version 4.8.0 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-62781
GHSA-M8W5-8W3H-72WM

Affected Products

Bigbluebutton
Pilos