PT-2022-3299 · Trueconf · Trueconf Server

Liquidworm

·

Published

2022-06-29

·

Updated

2023-04-20

·

CVE-2017-20114

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TrueConf Server version 4.3.7
Description A vulnerability has been found in the /admin/conferences/get-all-status/ component of TrueConf Server, related to the failure to neutralize script-related HTML tags on a web page. The manipulation of the keys[] argument leads to basic cross-site scripting (Reflected). The attack can be initiated remotely.
Recommendations For TrueConf Server version 4.3.7, consider disabling access to the /admin/conferences/get-all-status/ endpoint until a patch is available. Restrict the use of the keys[] argument in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-04037
CVE-2017-20114

Affected Products

Trueconf Server