CVE-2017-15687
MEDIUMLogitech Media Server 7.7.1-7.7.3 7.7.5-7.7.6 7.9.0-7.9.1 - DOM-Based Cross-Site Scripting via Crafted URI
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15687. PoCs published by Thiago Sena.
AI-analyzed exploit summary This exploit demonstrates a DOM-based XSS vulnerability in Logitech Media Server by injecting a malicious script via the URL path. The PoC shows how arbitrary JavaScript can be executed in the context of the victim's browser session.
Description
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
Exploits (1)
This exploit demonstrates a DOM-based XSS vulnerability in Logitech Media Server by injecting a malicious script via the URL path. The PoC shows how arbitrary JavaScript can be executed in the context of the victim's browser session.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N