{"api_version":"1","generated_at":"2026-04-24T05:50:18+00:00","cve":"CVE-2017-20113","urls":{"html":"https://cve.report/CVE-2017-20113","api":"https://cve.report/api/cve/CVE-2017-20113.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-20113","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-20113"},"summary":{"title":"CVE-2017-20113","description":"A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-06-29 17:15:00","updated_at":"2023-04-20 18:23:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/41184/","name":"https://www.exploit-db.com/exploits/41184/","refsource":"MISC","tags":[],"title":"TrueConf Server 4.3.7 - Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://vuldb.com/?id.96627","name":"https://vuldb.com/?id.96627","refsource":"MISC","tags":[],"title":"CVE-2017-20113 | TrueConf Server Stored cross site scripting (EDB-41184 / EDB-41184)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-20113","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20113","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"20113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trueconf","cpe5":"server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"20113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trueconf","cpe5":"server","cpe6":"4.3.7.12219","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"20113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trueconf","cpe5":"server","cpe6":"4.3.7.12255","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2017-20113","TITLE":"TrueConf Server Stored cross site scripting","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"TrueConf","product":{"product_data":[{"product_name":"Server","version":{"version_data":[{"version_value":"4.3.7"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-80 Basic Cross Site Scripting"}]}]},"description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."}]},"credit":"LiquidWorm","impact":{"cvss":{"version":"3.1","baseScore":"3.5","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}},"references":{"reference_data":[{"url":"https://www.exploit-db.com/exploits/41184/","refsource":"MISC","name":"https://www.exploit-db.com/exploits/41184/"},{"url":"https://vuldb.com/?id.96627","refsource":"MISC","name":"https://vuldb.com/?id.96627"}]}},"nvd":{"publishedDate":"2022-06-29 17:15:00","lastModifiedDate":"2023-04-20 18:23:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trueconf:server:*:*:*:*:*:*:*:*","versionEndExcluding":"5.0.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}