CNNVD-202512-5085 Information
Dec 30, 2025
cve
CNNVD ID
CNNVD-202512-5085
Related CVE
- CNNVD Published: 2025-12-30
Description (Chinese)
TrueConf Server是俄罗斯TrueConf公司的一种自托管和安全的视频协作平台。 TrueConf Server 5.5.2.10813版本存在安全漏洞,该漏洞源于允许通过特制显示名称注入恶意电子表格公式,可能导致CSV公式注入攻击。
Description (English)
TrueConf Server is a self-hosted and secure video-collaboration platform for TrueConf, Russia. TrueConf Server 5.5.2.10813 has a security loophole, which stems from allowing the introduction of malicious spreadsheet formulae through the display of a unique name, which could lead to an attack by the CSV formula.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
TrueConf
Published
2025-12-30
Last Modified
2026-02-24
References
https://github.com/x00nullbit/CVE-References/blob/main/CVE-2025-66834/README.md https://trueconf.com https://access.redhat.com/security/cve/cve-2025-66834
Patch
https://trueconf.com/products/tcsf/trueconf-server-free.html
Share on: