VYPR
High severity7.3NVD Advisory· Published Dec 30, 2025· Updated Aug 20, 2026

CVE-2025-66834

CVE-2025-66834

Description

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Trueconf/Server2 versions
    cpe:2.3:a:trueconf:server:5.5.2.10813:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trueconf:server:5.5.2.10813:*:*:*:*:*:*:*
    • (no CPE)
  • Range: = 5.5.2.10813

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.