CVE-2017-20117
LOWTrueConf Server < 5.0.2 - Cross-Site Scripting in /admin/group
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20117. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
Description
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N