Impact
PILOS, the frontend for BigBlueButton, was missing the Cross‑Origin‑Opener‑Policy header between versions 2.1.0 and 4.14.1. Without the header, pages opened from PILOS using a target="_blank" attribute maintain a window.opener reference to the originating tab. A malicious page opened in that way can exploit window.opener to navigate or manipulate the original PILOS tab. This reverse tabnabbing attack could lead an authenticated user to a phishing page that closely resembles PILOS, potentially allowing credential theft or session hijacking. The weakness corresponds to CWE‑1022.
Affected Systems
The vulnerability affects the THM‑Health PILOS application, specifically all releases from 2.1.0 up to and including 4.14.1. An upgrade to version 4.14.1 or later resolves the issue.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attack feasibility requires a user to follow a link that opens a new window; the attacker can then manipulate the original tab through window.opener. The risk is therefore limited to contexts where users interact with unknown external links on PILOS pages. No additional exploitation steps are described in the input data.
OpenCVE Enrichment