Persistent Cross-Site Scripting Vulnerability in Logitech Media Server
CVE-2017-16567
5.4MEDIUM
Key Information:
- Vendor
Logitech
- Status
- Vendor
- CVE Published:
- 10 November 2017
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2017-16567?
The vulnerability in Logitech Media Server 7.9.0 allows remote attackers to exploit the 'Favorites' feature, enabling them to inject and store malicious JavaScript code. This exploits the system when affected users access certain functionalities. Victims may face severe consequences including unauthorized actions performed on their behalf, session hijacking, credential theft, and the risk of sensitive data exfiltration. This issue poses a significant threat in IoT environments where Logitech devices operate.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
