Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
History

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mirotalk
Mirotalk mirotalk P2p
Weaknesses CWE-924
CPEs cpe:2.3:a:mirotalk:mirotalk_p2p:*:*:*:*:*:*:*:*
Vendors & Products Mirotalk
Mirotalk mirotalk P2p
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-11T00:00:00

Updated: 2024-10-16T18:49:03.178Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44730

cve-icon Vulnrichment

Updated: 2024-10-16T18:40:01.253Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-11T16:15:08.250

Modified: 2024-10-16T19:35:08.430

Link: CVE-2024-44730

cve-icon Redhat

No data.