First published: Wed Apr 14 2021(Updated: )
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
8x8 Jitsi Meet | >=2.7<=2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26812 is a Cross Site Scripting (XSS) vulnerability in the Jitsi Meet plugin for Moodle.
CVE-2021-26812 allows attackers to craft a malicious URL that can inject javascript code when clicked on by users.
The severity of CVE-2021-26812 is medium with a CVSS score of 6.1.
The Jitsi Meet plugin for Moodle versions 2.7 through 2.8.3 is affected by CVE-2021-26812.
To fix CVE-2021-26812, you should update your Jitsi Meet plugin for Moodle to a version that is not affected by the vulnerability.