PT-2024-33560 · Unknown · Avchat Video Chat

·

CVE-2024-49605

·

Published

2024-10-20

·

Updated

2024-10-24

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions AVChat Video Chat versions n/a through 2.2
Description A Cross-Site Request Forgery (CSRF) vulnerability is present in AVChat Video Chat, allowing Stored Cross Site Scripting (XSS). This issue enables attackers to perform unauthorized actions on behalf of a user.
Recommendations For versions n/a through 2.2, update to a version above 2.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features of AVChat Video Chat to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-49605

Affected Products

Avchat Video Chat