CVE-2017-20120: TrueConf Server cross-site request forgery
Published Jun 29, 2022
·Updated
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
4 affected components
TrueConf Server=4.3.7.12219
TrueConf Server=4.3.7.12255
TrueConf TrueConf Server=4.3.7.12219
TrueConf TrueConf Server=4.3.7.12255
Event History
Jun 29, 2022
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-20120?
The severity of CVE-2017-20120 is high with a severity value of 8.8.
2
What is affected by CVE-2017-20120?
TrueConf Server versions 4.3.7.12219 and 4.3.7.12255 are affected by CVE-2017-20120.
3
What is the vulnerability in CVE-2017-20120?
The vulnerability in CVE-2017-20120 is a cross-site request forgery vulnerability in the file /admin/service/stop/ of TrueConf Server.
4
How can the vulnerability in CVE-2017-20120 be exploited?
The vulnerability in CVE-2017-20120 can be exploited remotely.
5
Are there any known exploits for CVE-2017-20120?
Yes, there are known exploits for CVE-2017-20120, which have been disclosed to the public.