CVE-2017-20113

LOW

TrueConf Server 4.3.7 - XSS

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/41184

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/41184/
Permissions Required, Third Party Advisory, VDB Entry x_refsource_misc
https://vuldb.com/?id.96627

Scores

CVSS v3 3.5
EPSS 0.0019
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
trueconf/server < 5.0.2
Published Jun 29, 2022
Tracked Since Feb 18, 2026