CVE-2020-12113: XSS
Published Apr 23, 2020
·Updated
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
Affected Software
1 affected component
BigBlueButton BigBlueButton<2.2.4
Remediation
Patch Available
Event History
Apr 23, 2020
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12113?
CVE-2020-12113 is a vulnerability in BigBlueButton before version 2.2.4 that allows XSS attacks via closed captions.
2
How severe is CVE-2020-12113?
CVE-2020-12113 has a severity rating of medium (6.1 out of 10).
3
How does CVE-2020-12113 occur?
CVE-2020-12113 occurs because BigBlueButton uses dangerouslySetInnerHTML in React, allowing XSS attacks through closed captions.
4
What software versions are affected by CVE-2020-12113?
BigBlueButton versions up to 2.2.4 are affected by CVE-2020-12113.
5
How can I fix CVE-2020-12113?
To fix CVE-2020-12113, you should update your BigBlueButton installation to version 2.2.4 or later.