CVE-2020-29043

HIGH

BigBlueButton < 2.2.29 - Unauthenticated Email Validation Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

References (3)

Core 3
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/bigbluebutton/bigbluebutton/releases
Exploit, Third Party Advisory x_refsource_misc
https://cxsecurity.com/issue/WLB-2020110211

Scores

CVSS v3 7.5
EPSS 0.0143
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-200
Status published
Products (1)
bigbluebutton/bigbluebutton < 2.2.29
Published Nov 26, 2020
Tracked Since Feb 18, 2026