CVE-2017-20114
LOWTrueConf Server < 5.0.2 - Reflected Cross-Site Scripting via keys[] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20114. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
Description
A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N