CNNVD-202512-5087 Information

CNNVD ID

CNNVD-202512-5087

CVE-2025-66824

  • CNNVD Published: 2025-12-30

Description (Chinese)

TrueConf Server是俄罗斯TrueConf公司的一种自托管和安全的视频协作平台。 TrueConf Server 5.5.2.10813版本存在安全漏洞,该漏洞源于会议地点字段对用户输入清理不当,可能导致存储型跨站脚本攻击和账户接管。

Description (English)

TrueConf Server is a self-hosted and secure video-collaboration platform for TrueConf, Russia. TrueConf Server 5.5.2.108113 has a security loophole, which stems from the improper clean-up of user input in the Conference site field, which may result in a storage-type cross-site script attack and account take-over.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

TrueConf

Published

2025-12-30

Last Modified

2026-02-24

References

https://github.com/x00nullbit/CVE-References/blob/main/CVE-2025-66824/README.md https://trueconf.com https://access.redhat.com/security/cve/cve-2025-66824

Patch

https://trueconf.com/products/tcsf/trueconf-server-free.html

Share on: