CSV Formula Injection Vulnerability in TrueConf Server by TrueConf
CVE-2025-66834
7.3HIGH
What is CVE-2025-66834?
A vulnerability exists in TrueConf Server v5.5.2.10813 that permits a standard user to exploit CSV formula injection. This occurs through the manipulation of the Display Name in exported chat logs, enabling the injection of malicious spreadsheet formulas. As a result, any unsuspecting user opening the affected CSV files may inadvertently execute harmful commands or scripts designed to compromise their system.
