Impact
BigBlueButton is an open-source virtual classroom platform. In versions prior to 3.0.21, the bbb-web component’s checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java. As a result, an attacker can send valid requests to some endpoints without a checksum, effectively bypassing the intended security check. This flaw permits unauthorized API usage, such as uploading content from an external URL, and is classified as an improper authorization vulnerability (CWE-284).
Affected Systems
The affected product is BigBlueButton, specifically versions prior to 3.0.21. Users running older versions of the bbb-web component are at risk. The issue does not affect later releases.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not yet listed in the CISA KEV catalog, meaning no known widespread exploitation has been documented. Nevertheless, because the flaw allows bypassing a critical security check, an attacker could potentially conduct unauthorized API requests if they can reach the target system.
OpenCVE Enrichment