<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Closed Captions on Saksham Anand</title>
    <link>/tags/closed-captions/</link>
    <description>Recent content in Closed Captions on Saksham Anand</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Apr 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/closed-captions/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2020-12113 BigBlueButton | Closed Captions XSS</title>
      <link>/blog/cve-2020-12113/</link>
      <pubDate>Mon, 20 Apr 2020 00:00:00 +0000</pubDate>
      <guid>/blog/cve-2020-12113/</guid>
      <description>As part of a penetration testing project at Catalyst IT, I conducted a test on an open source video conferencing system known as the BigBlueButton, an open source challenger to Zoom.
The BigBlueButton contains a closed captions module, that allows a user to manually type captions, and all users with captions enabled can see them at the bottom of the screen. While the ability to add captions is only restricted to moderator level permissions, this issue is exaggerated, as when the breakout room functionality is used, all users are granted moderator level permissions, allowing them to write captions.</description>
    </item>
  </channel>
</rss>
