PT-2017-14451 · Logitech · Logitech Media Server
Dewank Pant
·
Published
2017-11-09
·
Updated
2025-02-04
·
CVE-2017-16567
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Logitech Media Server version 7.9.0
Description
The issue is related to a Cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via a
favorite. This vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. It presents a potential risk for widespread exploitation in connected IoT environments.Recommendations
For Logitech Media Server version 7.9.0, consider disabling the
Favorites feature until a patch is available to prevent the injection and permanent storage of malicious JavaScript payloads. Restrict access to the affected functionality to minimize the risk of exploitation. Avoid using the favorite feature in the affected version until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logitech Media Server