CVE-2025-66823: XSS
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66823?
The severity of CVE-2025-66823 is considered to be high due to its potential to allow arbitrary HTML injection.
How do I fix CVE-2025-66823?
To fix CVE-2025-66823, ensure that TrueConf Server is updated to the latest version that addresses this vulnerability.
What impact does CVE-2025-66823 have on TrueConf Server?
CVE-2025-66823 allows attackers to inject arbitrary HTML into the conference description, which can lead to various attacks such as phishing.
Is CVE-2025-66823 easy to exploit?
CVE-2025-66823 is relatively easy to exploit if an attacker has access to the Create/Edit conference functionality.
Which versions of TrueConf Server are affected by CVE-2025-66823?
CVE-2025-66823 specifically affects TrueConf Server version 5.5.2.10813.