{"containers":{"cna":{"affected":[{"product":"Server","vendor":"TrueConf","versions":[{"status":"affected","version":"4.3.7"}]}],"credits":[{"lang":"en","value":"LiquidWorm"}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-80","description":"CWE-80 Basic Cross Site Scripting","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2022-06-29T16:15:24.000Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"tags":["x_refsource_MISC"],"url":"https://www.exploit-db.com/exploits/41184/"},{"tags":["x_refsource_MISC"],"url":"https://vuldb.com/?id.96627"}],"title":"TrueConf Server Stored cross site scripting","x_generator":"vuldb.com","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2017-20113","REQUESTER":"cna@vuldb.com","STATE":"PUBLIC","TITLE":"TrueConf Server Stored cross site scripting"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Server","version":{"version_data":[{"version_value":"4.3.7"}]}}]},"vendor_name":"TrueConf"}]}},"credit":"LiquidWorm","data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."}]},"generator":"vuldb.com","impact":{"cvss":{"baseScore":"3.5","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-80 Basic Cross Site Scripting"}]}]},"references":{"reference_data":[{"name":"https://www.exploit-db.com/exploits/41184/","refsource":"MISC","url":"https://www.exploit-db.com/exploits/41184/"},{"name":"https://vuldb.com/?id.96627","refsource":"MISC","url":"https://vuldb.com/?id.96627"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T21:45:25.997Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.exploit-db.com/exploits/41184/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://vuldb.com/?id.96627"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-14T17:07:03.202510Z","id":"CVE-2017-20113","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-15T14:10:05.044Z"}}]},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2017-20113","datePublished":"2022-06-29T16:15:24.000Z","dateReserved":"2022-06-27T00:00:00.000Z","dateUpdated":"2025-04-15T14:10:05.044Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}