CVE-2025-66824
Stored XSS in TrueConf Server Meeting Location Enables Account Takeover
Publication date: 2025-12-30
Last updated on: 2025-12-30
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trueconf | trueconf_server | 5.5.2.10813 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Meeting location field of the Create/Edit Conference feature in TrueConf Server v5.5.2.10813. An attacker can inject malicious code via the meeting_room parameter, which is improperly sanitized. This malicious code is then stored and executed when users visit the Conference Info page, potentially allowing the attacker to take over user accounts.
How can this vulnerability impact me? :
The vulnerability can lead to full Account Takeover (ATO) for users who visit the affected Conference Info page. This means attackers can gain unauthorized access to user accounts, potentially compromising sensitive information and control over the affected accounts.