Cross-site scripting in BigBlueButton - CVE-2022-31065
Published: June 22, 2022 / Updated: May 14, 2026
BigBlueButton
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in the private chat username handling when rendering private chat messages or leave notifications. A remote user can embed malicious JavaScript in a username to execute arbitrary JavaScript in the victim's browser.
User interaction is required for the victim to receive a private chat message or a notification that the sender left the session.