CVE-2025-66824
Unknown Unknown - Not Provided
Stored XSS in TrueConf Server Meeting Location Enables Account Takeover

Publication date: 2025-12-30

Last updated on: 2025-12-30

Assigner: MITRE

Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-30
Last Modified
2025-12-30
Generated
2026-05-07
AI Q&A
2025-12-30
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
trueconf trueconf_server 5.5.2.10813
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Meeting location field of the Create/Edit Conference feature in TrueConf Server v5.5.2.10813. An attacker can inject malicious code via the meeting_room parameter, which is improperly sanitized. This malicious code is then stored and executed when users visit the Conference Info page, potentially allowing the attacker to take over user accounts.


How can this vulnerability impact me? :

The vulnerability can lead to full Account Takeover (ATO) for users who visit the affected Conference Info page. This means attackers can gain unauthorized access to user accounts, potentially compromising sensitive information and control over the affected accounts.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart