VYPR
Vendor

Miroslavpejic85

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2024-44730CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.

  • CVE-2024-44734HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

  • CVE-2024-44729HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.

  • CVE-2024-44731MedOct 11, 2024
    risk 0.31cvss 4.7epss 0.01

    Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.