PT-2025-54215 · Trueconf · Trueconf Server

X00Nullbit

·

Published

2025-12-30

·

Updated

2026-01-02

·

CVE-2025-66824

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TrueConf Server version 5.5.2.10813
Description A Stored Cross-Site Scripting (XSS) issue exists in the Meeting location field within the Create/Edit Conference functionality. The issue is due to improper sanitization of user-supplied input in the meeting room parameter. An attacker can inject a malicious payload into the meeting room parameter, which is then stored and executed when users access the Conference Info page. Successful exploitation of this issue can lead to full Account Takeover (ATO).
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting or disabling the Create/Edit Conference functionality until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-04922
CVE-2025-66824

Affected Products

Trueconf Server