PT-2025-44055 · Unknown+1 · Bigbluebutton+1
Published
2025-10-27
·
Updated
2025-10-28
·
CVE-2025-62781
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PILOS versions prior to 4.8.0
Description
PILOS, a frontend for BigBlueButton, contains a flaw where changing a local user’s password does not invalidate existing session tokens, except for the current session. An attacker who previously obtained a valid session token can maintain access even after the user changes their password. The issue occurs because the current session’s token remains valid after the password change. This allows continued unauthorized access as the user.
Recommendations
Update to version 4.8.0 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton
Pilos