PT-2022-7986 · Trueconf · Trueconf Server
Liquidworm
·
Published
2022-06-29
·
Updated
2023-04-20
·
CVE-2017-20117
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TrueConf Server version 4.3.7
Description
A vulnerability was found in an unknown functionality of the file /admin/group, leading to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations
For TrueConf Server version 4.3.7, consider restricting access to the /admin/group file until a patch is available. As a temporary workaround, avoid using the affected functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trueconf Server