CVE-2022-46764

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trueconf:server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-12-27 01:15

Updated : 2026-01-21 16:16


NVD link : CVE-2022-46764

Mitre link : CVE-2022-46764

CVE.ORG link : CVE-2022-46764


JSON object : View

Products Affected

microsoft

  • windows

trueconf

  • server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')