Vulnerability Description
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jitsi | Meet | >= 2.7, <= 2.8.3 |
Related Weaknesses (CWE)
References
- https://github.com/udima-university/moodle-mod_jitsi/issues/67ExploitIssue TrackingThird Party Advisory
- https://github.com/udima-university/moodle-mod_jitsi/issues/67ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-26812?
CVE-2021-26812 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can i...
How severe is CVE-2021-26812?
CVE-2021-26812 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26812?
Check the references section above for vendor advisories and patch information. Affected products include: Jitsi Meet.