CVE-2017-20120
MEDIUMTrueConf Server 4.3.7 - Cross-Site Request Forgery in Admin Service Stop Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20120. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
Description
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
The exploit demonstrates multiple web vulnerabilities in TrueConf Server v4.3.7, including CSRF, stored/reflected/DOM XSS, and open redirect. It provides PoC code and URLs to trigger these issues, primarily targeting administrative interfaces.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N