#VU48706 Missing Authorization in BigBlueButton - CVE-2020-29043
Published: November 26, 2020 / Updated: November 30, 2020
BigBlueButton
Blindside Networks
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to missing authorization in the "account_activations/edit?token=" URI. A remote attacker can create an approved user account associated with an email address that has an arbitrary domain name.