Moodle Jitsi Meet 2.7 through 2.8.3 plugin contains a cross-site scripting vulnerability via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject JavaScript code to be run by the application.
id: CVE-2021-26812
info:
name: Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scripting
author: acese
...