---
id: CVE-2025-62523
title: >-
  PILOS (Platform for Interactive Live-Online Seminars) is a frontend for
  BigBlueButton
summary: >-
  PILOS (Platform for Interactive Live-Online Seminars) is a frontend for
  BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing
  (CORS) misconfiguration in its middleware: it reflects the Origin request
  header back in t…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-942
vendor: thm
product: pilos
affected:
  - pilos < 4.8.0
patched:
  - pilos 4.8.0
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62523'
references:
  - url: >-
      https://github.com/THM-Health/PILOS/commit/14655bc4f8128ffd2b3c25004b01d9a802808da8
    label: security-advisories@github.com
  - url: >-
      https://github.com/THM-Health/PILOS/security/advisories/GHSA-pgfw-f4mp-5445
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00204
epssPercentile: 0.0946
ingestedAt: '2026-10-08T11:31:27.649Z'
---

## Overview

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior could allow a malicious website on a different origin to send requests (including credentials) to the PILOS API. This may enable exfiltration or actions using the victim’s credentials if the server accepts those cross-origin requests as authenticated. Laravel’s session handling applies additional origin checks such that cross-origin requests are not authenticated by default. Because of these session-origin protections, and in the absence of any other unknown vulnerabilities that would bypass Laravel’s origin/session checks, this reflected-Origin CORS misconfiguration is not believed to be exploitable in typical PILOS deployments. This vulnerability has been patched in PILOS in v4.8.0

## Affected

- `pilos < 4.8.0`

## Remediation

Upgrade past the affected range:

- `pilos 4.8.0`
