CVE-2022-46764

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trueconf:server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

27 Feb 2026, 18:16

Type Values Removed Values Added
Summary (en) A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. (en) A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

21 Jan 2026, 16:16

Type Values Removed Values Added
Summary (en) A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. (en) A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://github.com/sldlb/public_cve_submissions/blob/main/CVE-2022-46764.txt - Third Party Advisory () https://github.com/sldlb/public_cve_submissions/blob/main/CVE-2022-46764.txt - Third Party Advisory
References () https://solidlab.ru/our-news/145-trueconf.html - Third Party Advisory () https://solidlab.ru/our-news/145-trueconf.html - Third Party Advisory
References () https://vuldb.com/?diff.216845 - () https://vuldb.com/?diff.216845 -

26 Apr 2023, 00:15

Type Values Removed Values Added
References
  • (MISC) https://vuldb.com/?diff.216845 -

Information

Published : 2022-12-27 01:15

Updated : 2026-02-27 18:16


NVD link : CVE-2022-46764

Mitre link : CVE-2022-46764

CVE.ORG link : CVE-2022-46764


JSON object : View

Products Affected

trueconf

  • server

microsoft

  • windows
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')