SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26812

Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module.

MEDIUM 6.1EPSS 97.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 97.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
97.46% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jitsi/meet
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.