CVE-2022-46763: TrueConf Server
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
Affected products
- TrueConf Server: before 5.2.6 (fixed in 5.2.6)
Published 2022-12-27. Last modified 2026-06-17.