CVE-2017-20116
LOWTrueConf Server < 5.0.2 - Reflected Cross-Site Scripting via checked_group_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20116. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
Description
A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N