5
CVSSv2

CVE-2020-12112

Published: 23/04/2020 Updated: 05/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

BigBlueButton prior to 2.2.5 allows remote malicious users to obtain sensitive files via Local File Inclusion.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bigbluebutton bigbluebutton

Github Repositories

BigBlueButton versions lower than 2.2.4 have a LFI vulnerability allowing access to sensitive files. 🚨

CVE-2020-12112 🚨 BigBlueButton versions lower than 224 have a LFI vulnerability allowing access to sensitive files Story πŸ“œ During a distance learning course on a BigBlueButton instance a student in my class shared my teacher's slide presentation link and I noticed that the file name was included in the URL Student: "No need to write notes, I've got the