CVE-2025-66824
published 2025-12-30CVE-2025-66824: A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server…
PriorityP343high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.31%
21.9th percentile
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trueconf | trueconf_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TrueConf Server 5.5.2.10813 Conference Info Page meeting_room cross site scripting
vuldb·2026-08-22·CVSS 8.7
CVE-2025-66824 [HIGH] TrueConf Server 5.5.2.10813 Conference Info Page meeting_room cross site scripting
A vulnerability identified as problematic has been detected in TrueConf Server 5.5.2.10813. Affected by this issue is some unknown functionality of the component Conference Info Page. The manipulation of the argument meeting_room leads to cross site scripting.
This vulnerability is documented as CVE-2025-66824. The attack can be initiated remotely. There is not any exploit available.
GHSA
GHSA-wc9p-rvp2-mc4r: A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server
ghsa_unreviewed·2025-12-30
CVE-2025-66824 [HIGH] CWE-79 GHSA-wc9p-rvp2-mc4r: A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-30
Published