VulnerabilityModified
CVE-2021-26812
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module.
MEDIUM 6.1EPSS 97.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 97.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 97.46% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jitsi/meet
- Source
- cve@mitre.org
References
- https://github.com/udima-university/moodle-mod_jitsi/issues/67Exploit, Issue Tracking, Third Party Advisory
- https://github.com/udima-university/moodle-mod_jitsi/issues/67Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.