Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the return_to cookie. Versions 2.13.0 contains a patch for the issue.
{
"cwe_ids": [
"CWE-601"
]
}