PT-2022-27977 · Trueconf · Trueconf Server
Андрей Ситников
+2
·
Published
2022-11-28
·
Updated
2026-02-09
·
CVE-2022-46763
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TrueConf Server version 5.2.0.10225
Description
A SQL injection issue in a database stored function allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
Recommendations
For TrueConf Server version 5.2.0.10225, consider restricting database access to prevent low-privileged users from executing arbitrary SQL commands until a patch is available. As a temporary workaround, limit the privileges of the database user to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trueconf Server