CVE-2017-20120

Executive Summary

Cross‑site request forgery vulnerability in TrueConf Server 4.3.7 allows remote attackers to trigger privileged actions via the /admin/service/stop/ endpoint without authentication. The flaw can be exploited over the network, potentially leading to unauthorized service termination or other privileged operations. No patch status indicated; public exploit available.


Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2022-06-29T17:15:08.197 - Last Modified: 2026-08-20T19:14:38.670

Original Description: A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

"Learning without reflection is a waste, reflection without learning is dangerous."

— Confucius
Source: NVD