CVE-2024-44731
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/10/2024
Last modified:
15/04/2026
Description
Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM



