BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "Shared Notes" page, when a user with a malicious username is editing content. This vulnerability allows a low-privileged user to execute arbitrary JavaScript in the context of higher-privileged users (e.g., Admins) who open the Shared Notes page. Version 3.0.13 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:* |
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bigbluebutton
Bigbluebutton bigbluebutton |
|
| Vendors & Products |
Bigbluebutton
Bigbluebutton bigbluebutton |
Thu, 09 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "Shared Notes" page, when a user with a malicious username is editing content. This vulnerability allows a low-privileged user to execute arbitrary JavaScript in the context of higher-privileged users (e.g., Admins) who open the Shared Notes page. Version 3.0.13 fixes the issue. | |
| Title | BigBlueButton vulnerable to Stored XSS via name of user at Shared Notes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-09T18:51:57.884Z
Updated: 2025-10-09T19:08:17.415Z
Reserved: 2025-08-08T21:55:07.965Z
Link: CVE-2025-55200
Updated: 2025-10-09T19:08:14.974Z
Status : Analyzed
Published: 2025-10-09T19:15:43.663
Modified: 2025-10-20T15:30:19.377
Link: CVE-2025-55200
No data.