CVE-2020-29043

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/11/2020
Last modified:
21/07/2021

Description

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:* 2.2.29 (including)