Trueconf

Server

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 07.01.2026 15:39:50

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 07.01.2026 15:41:22

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 30.12.2025 00:00:00
  • Zuletzt bearbeitet 07.01.2026 15:39:03

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Confer...

  • EPSS 27.86%
  • Veröffentlicht 27.12.2022 01:15:11
  • Zuletzt bearbeitet 27.02.2026 18:16:06

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

  • EPSS 1.45%
  • Veröffentlicht 27.12.2022 01:15:10
  • Zuletzt bearbeitet 09.02.2026 16:15:57

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:40

A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can b...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:41

A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripti...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:41

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate t...

  • EPSS 0.13%
  • Veröffentlicht 29.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:41

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The ex...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 29.06.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 03:22:39

A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has bee...