CVE-2017-20119

LOW

TrueConf Server 4.3.7 - Open Redirect

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/41184

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/41184/
Permissions Required, Third Party Advisory, VDB Entry x_refsource_misc
https://vuldb.com/?id.96633

Scores

CVSS v3 3.5
EPSS 0.0025
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
trueconf/server < 5.0.2
Published Jun 29, 2022
Tracked Since Feb 18, 2026