CVE-2017-20114: TrueConf Server Reflected cross site scripting
Published Jun 29, 2022
·Updated
A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
TrueConf Server<5.0.2
Event History
Jun 29, 2022
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-20114?
The severity of CVE-2017-20114 is medium with a severity value of 5.4.
2
How does CVE-2017-20114 affect TrueConf Server software?
CVE-2017-20114 affects TrueConf Server software version up to 5.0.2.
3
What is the type of vulnerability in CVE-2017-20114?
CVE-2017-20114 is a basic cross-site scripting (Reflected) vulnerability.
4
Is CVE-2017-20114 exploitable remotely?
Yes, CVE-2017-20114 can be initiated remotely.
5
How can I fix CVE-2017-20114 in TrueConf Server?
To fix CVE-2017-20114, update TrueConf Server to version 5.0.2 or later.