CVE-2017-20117: TrueConf Server group DOM cross site scripting
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20117?
The severity of CVE-2017-20117 is medium with a severity value of 5.4.
What is affected by CVE-2017-20117?
TrueConf Server versions up to and excluding 5.0.2 are affected by CVE-2017-20117.
What is the CWE of CVE-2017-20117?
The CWE of CVE-2017-20117 is CWE-79 and CWE-80.
How can the exploit for CVE-2017-20117 be launched?
The exploit for CVE-2017-20117 can be launched remotely.
Where can I find more information about CVE-2017-20117?
More information about CVE-2017-20117 can be found at the following references: [Reference 1](https://vuldb.com/?id.96631) [Reference 2](https://www.exploit-db.com/exploits/41184/)