Vulnerability Description
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation of this vulnerability can lead to Session hijacking and unauthorized access, Persistent manipulation of web content within the application, and Phishing or malicious redirects to external domains. This vulnerability can be exploited to manipulate media server behavior in enterprise and home network environments.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Logitech | Media Server | 7.9.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/43123/Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43123/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2017-16568?
CVE-2017-16568 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, wh...
How severe is CVE-2017-16568?
CVE-2017-16568 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16568?
Check the references section above for vendor advisories and patch information. Affected products include: Logitech Media Server.