CVE-2017-20114

LOW

TrueConf Server < 5.0.2 - Reflected Cross-Site Scripting via keys[] Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20114. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.

Description

A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/41184

The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.

Classification
Working Poc 95%
Attack Type
Xss | Csrf | Auth Bypass | Other
Complexity
Trivial
Reliability
Reliable
Target: TrueConf Server v4.3.7.12255 and v4.3.7.12219
Auth required
Prerequisites: Access to administrative interface · User interaction for XSS/CSRF
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/41184/
Permissions Required, Third Party Advisory, VDB Entry x_refsource_misc
https://vuldb.com/?id.96628

Scores

CVSS v3 3.5
EPSS 0.0053
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
trueconf/server < 5.0.2
Published Jun 29, 2022
Tracked Since Feb 18, 2026