CVE-2024-44730 Information

Description

Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.

Reference

https://github.com/miroslavpejic85/mirotalk https://github.com/miroslavpejic85 https://aware7.com/de/blog/schwachstellen-in-videokonferenzsystemen/ https://github.com/miroslavpejic85/mirotalksfu/blob/main/SECURITY.md

Share on: