CVE-2020-27642: XSS
Published Oct 22, 2020
·Updated
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Affected Software
1 affected component
BigBlueButton Greenlight=2.7.6
Remediation
Patch Available
Event History
Oct 22, 2020
CVE Published
via MITRE·12:56 PM
Data Sourced
via MITRE·12:56 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27642?
CVE-2020-27642 is a cross-site scripting (XSS) vulnerability that exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
2
How severe is CVE-2020-27642?
CVE-2020-27642 has a severity keyword of 'medium' with a severity value of 6.1.
3
What is the affected software version of CVE-2020-27642?
The affected software version of CVE-2020-27642 is BigBlueButton Greenlight 2.7.6.
4
How can I fix CVE-2020-27642?
To fix CVE-2020-27642, users should update to a newer version of BigBlueButton Greenlight that includes the necessary patches.
5
Where can I find more information about CVE-2020-27642?
More information about CVE-2020-27642 can be found at the following link: [https://github.com/bigbluebutton/greenlight/pull/2214]