Clickjacking Vulnerability in Jitsi Web UI by Jitsi
CVE-2022-36736
6.1MEDIUM
What is CVE-2022-36736?
A vulnerability has been identified in the Jitsi Meet web UI that permits attackers to execute a clickjacking attack through specially crafted HTTP requests. This flaw potentially allows malicious actors to manipulate the user interface and mislead users into interacting with unintended elements on the page. Despite its implications, the vendor has disputed this finding, suggesting the need for careful assessment and testing to evaluate its actual impact. Users of Jitsi Meet are advised to remain vigilant and follow security best practices.
