PT-2025-54215 · Trueconf · Trueconf Server
X00Nullbit
·
Published
2025-12-30
·
Updated
2026-01-02
·
CVE-2025-66824
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TrueConf Server version 5.5.2.10813
Description
A Stored Cross-Site Scripting (XSS) issue exists in the Meeting location field within the Create/Edit Conference functionality. The issue is due to improper sanitization of user-supplied input in the
meeting room parameter. An attacker can inject a malicious payload into the meeting room parameter, which is then stored and executed when users access the Conference Info page. Successful exploitation of this issue can lead to full Account Takeover (ATO).Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting or disabling the Create/Edit Conference functionality until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trueconf Server