PT-2021-17145 · Moodle · Jitsi Meet

Purushottamanr

·

Published

2021-04-14

·

Updated

2021-04-21

·

CVE-2021-26812

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Jitsi Meet plugin for Moodle versions 2.7 through 2.8.3
Description: The issue allows attackers to craft a malicious URL that, when clicked on by users, can inject javascript code to be run by the application. This is achieved through a Cross Site Scripting (XSS) flaw in the sessionpriv.php module.
Recommendations: For versions 2.7 through 2.8.3, consider disabling the sessionpriv.php module until a patch is available to prevent potential exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26812

Affected Products

Jitsi Meet