CVE-2022-46763: TrueConf Server

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Affected products

  • TrueConf Server: before 5.2.6 (fixed in 5.2.6)

Published 2022-12-27. Last modified 2026-06-17.