CVE-2023-42803: BigBlueButton Unrestricted File Upload vulnerability
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42803?
CVE-2023-42803 is the identifier for the BigBlueButton Unrestricted File Upload vulnerability.
What is the severity of CVE-2023-42803?
CVE-2023-42803 has a severity rating of 8.8 (high).
How does the BigBlueButton Unrestricted File Upload vulnerability work?
The vulnerability occurs when the insertDocument API call in BigBlueButton does not properly validate the file extension before saving the file, allowing an attacker to upload malicious files.
Which versions of BigBlueButton are affected by CVE-2023-42803?
The vulnerability affects BigBlueButton versions up to and including 2.5.18.
How can I fix CVE-2023-42803?
To fix CVE-2023-42803, you should update to a version of BigBlueButton that is not affected by the vulnerability.