CVE-2017-15687

MEDIUM

Logitech Media Server - XSS

Title source: rule
STIX 2.1

Description

DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

Exploits (1)

exploitdb WORKING POC
by Thiago Sena · textwebappsmultiple
https://www.exploit-db.com/exploits/43024

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43024/

Scores

CVSS v3 6.1
EPSS 0.0083
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (7)
logitech/media_server 7.7.1
logitech/media_server 7.7.2
logitech/media_server 7.7.3
logitech/media_server 7.7.5
logitech/media_server 7.7.6
logitech/media_server 7.9.0
logitech/media_server 7.9.1
Published Oct 23, 2017
Tracked Since Feb 18, 2026