| ID | CVE-2020-25820 | ||||||
| Sažetak | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:S/C:P/I:N/A:N | ||||||
| Zadnje važnije ažuriranje | 29-10-2020 - 16:22 | ||||||
| Objavljeno | 21-10-2020 - 13:15 |

