CVE-2024-44734

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 16, 2024
CWE ID 346

Summary

CVE-2024-44734 is a newly disclosed vulnerability in Mirotalk. This issue stems from incorrect access control measures, allowing unauthorized users to manipulate username information. Attackers can exploit this vulnerability by sending a specially crafted roomAction request to the server. Successful exploitation enables the attacker to arbitrarily change targeted usernames, potentially leading to serious security implications. This vulnerability has been identified before the commitment of fix 9de226.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share