sldlb/public_cve_submissions

sldlb/public_cve_submissions

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

8.8 HIGH

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.