DOM Based Cross Site Scripting Vulnerability in Logitech Media Server
CVE-2017-15687

6.1MEDIUM

Key Information:

Vendor

Logitech

Vendor
CVE Published:
23 October 2017

What is CVE-2017-15687?

A DOM Based Cross Site Scripting vulnerability has been identified in Logitech Media Server, which affects multiple versions from 7.7.1 to 7.9.1. This vulnerability allows attackers to execute arbitrary JavaScript or HTML code within the browser's context by crafting a specially formatted URI. As a result, users may be susceptible to various malicious actions, including data theft or unauthorized actions. It is essential for users of the affected versions to apply necessary patches and updates to protect against potential exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.