CVE-2024-44731

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Nov 4, 2024
CWE ID 79

Summary

CVE-2024-44731 is a DOM-based cross-site scripting (XSS) vulnerability affecting Mirotalk before commit 9de226. This issue permits attackers to inject malicious code into messages sent over Real-Time Communication (RTC) connections. Successful exploitation allows the attacker to execute arbitrary code in the context of the targeted user, potentially leading to data theft or unauthorized actions. Users are advised to update their Mirotalk installation as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share