Record summary

CVE-2017-16568 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation of this vulnerability can lead to Session hijacking and unauthorized access, Persistent manipulation of web content within the application, and Phishing or malicious redirects to external domains. This vulnerability can be exploited to manipulate media server behavior in enterprise and home network environments.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBLogitech Media Server 7.9.0 - 'Radio URL' Cross-Site ScriptingExploitDB exploitby Dewank PantNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubdewankpant/CVE-2017-16568Repository PoCby dewankpantStars: 1Not analyzed1 file

555 B

GitHub

PoC details

References

2