CVE-2017-20120
גבוהה 8.8
תיאור (מקור, אנגלית)
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/9/2026
- CWE
- CWE-352
מוצרים מושפעים
trueconf: trueconf server
קישורים
- https://vuldb.com/?id.96634 Permissions RequiredThird Party Advisory
- https://www.exploit-db.com/exploits/41184/ Third Party AdvisoryVDB Entry
- https://vuldb.com/?id.96634 Permissions RequiredThird Party Advisory
- https://www.exploit-db.com/exploits/41184/ Third Party AdvisoryVDB Entry