Andrey Sitnikov

2 exploits Active since Dec 2022
CVE-2022-46763 WRITEUP HIGH WRITEUP
TrueConf Server <5.2.6.10025 - SQL Injection
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
CVSS 8.8
CVE-2022-46764 WRITEUP CRITICAL WRITEUP
TrueConf Server <5.2.6 - SQL Injection
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
CVSS 9.8