Lucene search

K
cvelistVulDBCVELIST:CVE-2017-20119
HistoryJun 29, 2022 - 4:15 p.m.

CVE-2017-20119 TrueConf Server change-lang redirect

2022-06-2916:15:33
CWE-601
VulDB
www.cve.org
vulnerability
trueconf server
change-lang
open redirect
cve-2017-20119
remote attack
exploit disclosed

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

44.8%

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CNA Affected

[
  {
    "product": "Server",
    "vendor": "TrueConf",
    "versions": [
      {
        "status": "affected",
        "version": "4.3.7"
      }
    ]
  }
]

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

44.8%

Related for CVELIST:CVE-2017-20119