Record summary

CVE-2017-16567 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected functionality. Exploitation of this vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. This vulnerability presents a potential risk for widespread exploitation in connected IoT environments.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBLogitech Media Server 7.9.0 - 'favorites' Cross-Site ScriptingExploitDB exploitby Dewank PantNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubdewankpant/CVE-2017-16567Repository PoCby dewankpantStars: 1Not analyzed1 file

515 B

GitHub

PoC details

References

2