Vulnerabilities
Vulnerable Software
Trueconf:  >> Server  >> 5.5.2.10813  Security Vulnerabilities
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-30
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
CVSS Score
8.7
EPSS Score
0.0
Published
2025-12-30
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-12-30


Contact Us

Shodan ® - All rights reserved