PT-2022-3298 · Trueconf · Trueconf Server

Liquidworm

·

Published

2022-06-29

·

Updated

2023-04-20

·

CVE-2017-20113

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TrueConf Server version 4.3.7
Description The issue is related to the failure to neutralize script-related HTML tags on a web page, which can lead to basic cross-site scripting (Stored). This can be initiated remotely. The exploit has been disclosed publicly and may be used. The manipulation affects an unknown part of the software.
Recommendations For TrueConf Server version 4.3.7, consider disabling the web interface or restricting access to it until a patch is available to prevent exploitation of the stored cross-site scripting issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-04036
CVE-2017-20113

Affected Products

Trueconf Server