A CSV Formula Injection vulnerability in TrueConf Server...
High severity
Unreviewed
Published
Dec 30, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2026
Description
Published by the National Vulnerability Database
Dec 30, 2025
Published to the GitHub Advisory Database
Dec 30, 2025
Last updated
Jan 2, 2026
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
References