CVE-2022-46763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
27/12/2022
Last modified:
11/04/2025

Description

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trueconf:server:*:*:*:*:*:*:*:* 5.2.6 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*