CVE-2025-66834
Executive Summary
A CSV Formula Injection flaw in TrueConf Server v5.5.2.10813 lets any authenticated user craft a malicious Display Name that is injected into exported chat logs. When the logs are opened in spreadsheet software, the injected formulas can execute, potentially leaking sensitive data, triggering unwanted actions, or facilitating phishing. The vulnerability does not require elevated privileges and can be exploited via normal user accounts.
Authoritative CVE Metadata - CVSS Base Score: 7.3 (HIGH) - Published: 2025-12-30T19:15:44.720 - Last Modified: 2026-08-20T18:09:37.043
Original Description: A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
"He who fears being conquered is sure of defeat."
— Napoleon Bonaparte