| Summary | Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server. |
|---|---|
| Publication Date | Oct. 12, 2024, 2:15 a.m. |
| Registration Date | Oct. 12, 2024, 5 a.m. |
| Last Update | Oct. 17, 2024, 4:35 a.m. |