Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
References
Configurations
No configuration.
History
16 Oct 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-924 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
15 Oct 2024, 12:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Oct 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-11 16:15
Updated : 2024-10-16 19:35
NVD link : CVE-2024-44730
Mitre link : CVE-2024-44730
CVE.ORG link : CVE-2024-44730
JSON object : View
Products Affected
No product.
CWE
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel