CVE-2022-46764: SQL Injection
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
Other sources
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46764?
CVE-2022-46764 is a SQL injection vulnerability in the web API of TrueConf Server 5.2.0.10225 that allows remote unauthenticated attackers to execute arbitrary SQL commands, leading to remote code execution.
What is the severity of CVE-2022-46764?
CVE-2022-46764 has a severity rating of 9.8 (Critical).
How does CVE-2022-46764 affect TrueConf Server?
CVE-2022-46764 affects TrueConf Server versions up to 5.2.6.
How can I fix CVE-2022-46764?
To fix CVE-2022-46764, update TrueConf Server to version 5.2.6 or higher.
Where can I find more information about CVE-2022-46764?
You can find more information about CVE-2022-46764 on the following sources: [GitHub](https://github.com/sldlb/public_cve_submissions/blob/main/CVE-2022-46764.txt), [SolidLab (Russian)](https://solidlab.ru/our-news/145-trueconf.html), [VulDB](https://vuldb.com/?diff.216845)