CVE-2024-44734 Information

Description

Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

Reference

https://github.com/miroslavpejic85/mirotalk https://github.com/miroslavpejic85 https://aware7.com/de/blog/schwachstellen-in-videokonferenzsystemen/ https://github.com/miroslavpejic85/mirotalksfu/blob/main/SECURITY.md

Share on: