CVE-2022-46764

CRITICAL

TrueConf Server <5.2.6 - SQL Injection

Title source: llm
STIX 2.1

Description

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

Scores

CVSS v3 9.8
EPSS 0.3152
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
trueconf/server < 5.2.6
Published Dec 27, 2022
Tracked Since Feb 18, 2026