PT-2022-3300 · Trueconf · Trueconf Server
Liquidworm
·
Published
2022-06-29
·
Updated
2023-04-20
·
CVE-2017-20116
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TrueConf Server version 4.3.7
Description
The issue is related to the failure to neutralize script-related HTML tags on the /admin/group/list/ webpage of the TrueConf Server software. This can allow a remote attacker to perform cross-site scripting attacks by manipulating the
checked group id argument. The attack can be launched remotely.Recommendations
For TrueConf Server version 4.3.7, consider disabling access to the /admin/group/list/ webpage until a patch is available. Restrict the use of the
checked group id argument in the affected webpage to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trueconf Server