Description
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
References
github.com/miroslavpejic85/mirotalk
aware7.com/de/blog/schwachstellen-in-videokonferenzsystemen/
github.com/miroslavpejic85/mirotalksfu/blob/main/SECURITY.md