CVE-2020-12113
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
Date published : 2020-04-23
https://github.com/bigbluebutton/bigbluebutton/pull/9017
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.2.4