CVE-2024-44730

Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
Configurations

No configuration.

History

16 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-924
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

15 Oct 2024, 12:58

Type Values Removed Values Added
Summary
  • (es) Un control de acceso incorrecto en la funciĆ³n handleDataChannelChat(dataMessage) de Mirotalk antes de el commit c21d58 permite a los atacantes falsificar mensajes de chat utilizando un nombre de remitente arbitrario.

11 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-11 16:15

Updated : 2024-10-16 19:35


NVD link : CVE-2024-44730

Mitre link : CVE-2024-44730

CVE.ORG link : CVE-2024-44730


JSON object : View

Products Affected

No product.

CWE
CWE-924

Improper Enforcement of Message Integrity During Transmission in a Communication Channel