CVE-2024-44729 Information
Nov 01, 2024
cve
Description
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
Reference
https://github.com/miroslavpejic85/mirotalk https://github.com/miroslavpejic85 https://aware7.com/de/blog/schwachstellen-in-videokonferenzsystemen/ https://github.com/miroslavpejic85/mirotalksfu/blob/main/SECURITY.md
Share on: