CVE-2017-20115: TrueConf Server Reflected cross site scripting
A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation of the argument sort leads to basic cross site scripting (Reflected). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-20115?
CVE-2017-20115 is a vulnerability found in TrueConf Server 4.3.7 that allows for basic cross-site scripting attacks.
What is the severity of CVE-2017-20115?
CVE-2017-20115 has a severity value of 5.4, which is considered medium.
How does CVE-2017-20115 impact TrueConf Server?
CVE-2017-20115 affects TrueConf Server 4.3.7 and versions up to exclusive 5.0.2 by allowing for basic cross-site scripting attacks through manipulation of the 'sort' argument in the /admin/conferences/list/ file.
Is CVE-2017-20115 exploitable remotely?
Yes, CVE-2017-20115 can be exploited remotely.
How can I fix CVE-2017-20115?
To fix CVE-2017-20115, you should update your TrueConf Server installation to a version beyond 5.0.2, which is not affected by this vulnerability.