PT-2017-14451 · Logitech · Logitech Media Server
Dewank Pant
·
Publicado
2017-11-09
·
Atualizado
2025-02-04
·
CVE-2017-16567
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Logitech Media Server version 7.9.0
Description
The issue is related to a Cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via a
favorite. This vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. It presents a potential risk for widespread exploitation in connected IoT environments.Recommendations
For Logitech Media Server version 7.9.0, consider disabling the
Favorites feature until a patch is available to prevent the injection and permanent storage of malicious JavaScript payloads. Restrict access to the affected functionality to minimize the risk of exploitation. Avoid using the favorite feature in the affected version until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Logitech Media Server