THREAT OPS › Threat News › [NVD] CVE-2025-66824 (HIGH 8.7) — A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page
[NVD] CVE-2025-66824 (HIGH 8.7) — A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page
CVE-2025-66824 CVSS: 8.7 HIGH Published: 2025-12-30T19:15:44.580
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover
Indicators of compromise
- CVE-2025-66824cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-66824