CVE-2022-46763 HIGH

CVE-2022-46763

Vendor Trueconf
Product TrueConf Server
Weakness CWE-89 · SQLi
Published December 27, 2022
Last update February 10, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Key dates

02Disclosure timeline

December 27, 2022 CVE published
February 10, 2026 Record updated