THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-66824 (HIGH 8.7) — A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page

[NVD] CVE-2025-66824 (HIGH 8.7) — A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page

lownvdPublished 2025-12-30

CVE-2025-66824 CVSS: 8.7 HIGH Published: 2025-12-30T19:15:44.580

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-66824