Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:trueconf:server:5.5.2.10813:*:*:*:*:*:*:* |
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trueconf
Trueconf server |
|
| Vendors & Products |
Trueconf
Trueconf server |
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 30 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-02T14:51:23.374Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66824
Updated: 2026-01-02T14:51:08.592Z
Status : Analyzed
Published: 2025-12-30T19:15:44.580
Modified: 2026-01-07T15:41:22.697
Link: CVE-2025-66824
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:22:15Z