Arbitrary Domain Name Account Creation Vulnerability in BigBlueButton

Arbitrary Domain Name Account Creation Vulnerability in BigBlueButton

CVE-2020-29043 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

Learn more about our User Device Pen Test.