PT-2024-31230 · Mirotalk · Mirotalk

Caio Fook

+3

·

Published

2024-10-11

·

Updated

2024-10-16

·

CVE-2024-44734

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mirotalk versions prior to commit 9de226
Description The issue is related to incorrect access control, allowing attackers to change usernames by sending a crafted roomAction request to the server.
Recommendations For versions prior to commit 9de226, update to a version that includes the fix for this issue, specifically commit 9de226 or later.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44734

Affected Products

Mirotalk