BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26163.json"