Cross-site scripting in BigBlueButton - CVE-2022-31064
Published: June 22, 2022 / Updated: May 14, 2026
BigBlueButton
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a stored cross-site scripting attack.
The vulnerability exists due to cross-site scripting in the username handling in private chat when sending private messages to users. A remote attacker can send a crafted private message to perform a stored cross-site scripting attack.
Only users in meetings with private chat enabled are affected.