CVE-2020-25820
MEDIUMBigBlueButton < 2.2.27 - Authenticated Server-Side Request Forgery via ODF xlink Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25820. PoCs published by RedTeam Pentesting GmbH.
AI-analyzed exploit summary This exploit leverages an arbitrary file disclosure and SSRF vulnerability in BigBlueButton by embedding XLinks in ODF documents, allowing attackers to read local files or perform server-side requests during document conversion.
Description
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
Exploits (1)
This exploit leverages an arbitrary file disclosure and SSRF vulnerability in BigBlueButton by embedding XLinks in ODF documents, allowing attackers to read local files or perform server-side requests during document conversion.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N