Directory Traversal Vulnerability in BigBlueButton by Blindspot Technologies
CVE-2020-12443
9.8CRITICAL
What is CVE-2020-12443?
The vulnerability in BigBlueButton allows remote attackers to exploit improper handling of filename casing to perform directory traversal attacks. By manipulating the 'presfilename' and 'presFilename' parameters, an attacker can read arbitrary files, including sensitive configuration files like bigbluebutton.properties. This flaw arose from a previous fix that inadequately addressed the underlying issue, primarily due to the case-insensitive nature of NGINX configurations. Such vulnerabilities highlight the critical need for robust input validation and thorough security practices within web applications.
