Description
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mirotalk
Mirotalk mirotalk P2p |
|
| Weaknesses | CWE-346 | |
| CPEs | cpe:2.3:a:mirotalk:mirotalk_p2p:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mirotalk
Mirotalk mirotalk P2p |
|
| Metrics |
cvssV3_1
|
Fri, 11 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-16T18:31:30.227Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44734
Updated: 2024-10-16T18:31:05.206Z
Status : Deferred
Published: 2024-10-11T17:15:04.157
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-44734
No data.
OpenCVE Enrichment
No data.
Weaknesses