BigBlueButton before 2.2.28 (or... CVE-2020-27606

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息