SQL Injection Vulnerability in TrueConf Server by TrueConf
CVE-2022-46763

8.8HIGH

Key Information:

Vendor

Trueconf

Vendor
CVE Published:
27 December 2022

What is CVE-2022-46763?

A vulnerability in TrueConf Server 5.2.0.10225 allows low-privileged database users to exploit a stored database function through SQL injection. This can lead to the execution of arbitrary SQL commands with the privileges of the database administrator, potentially enabling attackers to execute unauthorized code within the database environment.

Affected Version(s)

TrueConf Server 5.2.0.10225

TrueConf Server 5.2.6.10025

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.