cve/2020/CVE-2020-25820.md
2024-06-09 00:33:16 +00:00

961 B

CVE-2020-25820

Description

BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.

POC

Reference

Github

No PoCs found on GitHub currently.