CVE-2025-66824
Executive Summary
TrueConf Server v5.5.2.10813 contains a stored XSS flaw in the meeting_room field of the Create/Edit Conference interface. Malicious payloads are persisted and executed when the Conference Info page is viewed, enabling attackers to hijack user accounts and gain full account takeover. The vulnerability stems from inadequate input sanitization and is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.7 (HIGH) - Published: 2025-12-30T19:15:44.580 - Last Modified: 2026-08-20T18:09:50.830
Original Description: A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
"Fortune favours the brave."
— Virgil