Trueconf

Server

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 0.34%
  • Veröffentlicht 19.08.2026 16:56:53
  • Zuletzt bearbeitet 21.08.2026 04:18:15

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute...

Warnung Medienbericht Exploit
  • EPSS 0.28%
  • Veröffentlicht 19.08.2026 16:55:14
  • Zuletzt bearbeitet 21.08.2026 04:18:15

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 20.08.2026 18:09:37

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 20.08.2026 18:09:50

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users ...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 20.08.2026 18:09:27

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Confer...

  • EPSS 2.07%
  • Veröffentlicht 27.12.2022 01:15:11
  • Zuletzt bearbeitet 27.02.2026 18:16:06

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

  • EPSS 1.05%
  • Veröffentlicht 27.12.2022 01:15:10
  • Zuletzt bearbeitet 09.02.2026 16:15:57

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:40

A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can b...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:41

A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripti...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:41

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate t...