CVE-2025-66823
Unknown
Unknown - Not Provided
HTML Injection in TrueConf Server Conference Description Allows XSS
Publication date: 2025-12-30
Last updated on: 2025-12-30
Assigner: MITRE
Description
Description
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trueconf | server | 5.5.2.10813 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |