6.1
CVE-2022-36736
- EPSS 0.63%
- Veröffentlicht 08.09.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:13:37
- CVE-Watchlists
- Unerledigt
Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.469 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://github.com/UditChavda/Udit-Chavda-CVE/blob/main/CVE-2022-36736
https://meet.jit.si/