Stored Cross-Site Scripting Vulnerability in TrueConf Server
CVE-2025-66824

7.3HIGH

Key Information:

Vendor

TrueConf

Vendor
CVE Published:
30 December 2025

What is CVE-2025-66824?

A vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server version 5.5.2.10813, which allows for Stored Cross-Site Scripting (XSS) attacks. When a malicious user injects a payload into the meeting_room parameter, this input is improperly sanitized, leading to the execution of the script when other users view the Conference Info page. This oversight can result in unauthorized actions such as full account takeover, posing significant security risks to users.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.