Impact
A stored cross‑site scripting flaw was discovered in BigBlueButton’s screenshare recording playback feature. The meeting name entered by a user was not properly escaped when generating the playback page, allowing a malicious user to embed arbitrary JavaScript in the meeting title. When another user plays the recording, the script executes in that user’s browser, potentially exposing session cookies, personal data, or enabling further compromise of the client system.
Affected Systems
All BigBlueButton installations running a version earlier than 3.0.29 are affected. The flaw was addressed in the 3.0.29 release; therefore any deployment using v3.0.28 or earlier exposes its users to this vulnerability.
Risk and Exploitability
The CVSS score of 5.4 denotes a moderate impact. Because the attack requires a low-privileged user to create a meeting with a malicious name, the EPSS score is not available but the risk exists in environments where users can create meetings. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it by creating a malicious meeting name, saving it, and then convincing or waiting for a legitimate user to play the recording, at which point the injected script runs in that user’s browser.
OpenCVE Enrichment