CVE-2022-46763: SQL Injection
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
Other sources
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46763?
CVE-2022-46763 is a SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225.
How does CVE-2022-46763 impact TrueConf Server?
CVE-2022-46763 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
Which software versions are affected by CVE-2022-46763?
TrueConf Server versions up to exclusive 5.2.6 are affected by CVE-2022-46763.
What is the severity of CVE-2022-46763?
CVE-2022-46763 has a severity rating of 8.8 (high).
How can I fix CVE-2022-46763?
Upgrade TrueConf Server to version 5.2.6 or higher to mitigate CVE-2022-46763.