CVE-2017-15687: XSS
Published Oct 23, 2017
·Updated
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
Affected Software
7 affected components
Logitech Media Server=7.7.1
Logitech Media Server=7.7.2
Logitech Media Server=7.7.3
Logitech Media Server=7.7.5
Logitech Media Server=7.7.6
Logitech Media Server=7.9.0
Logitech Media Server=7.9.1
Event History
Oct 23, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15687?
CVE-2017-15687 has a moderate severity rating due to its potential impact on user data security.
2
How do I fix CVE-2017-15687?
To mitigate CVE-2017-15687, upgrade Logitech Media Server to the latest version that includes a patch.
3
What versions of Logitech Media Server are affected by CVE-2017-15687?
CVE-2017-15687 affects Logitech Media Server versions 7.7.1 through 7.9.1.
4
What is the nature of CVE-2017-15687?
CVE-2017-15687 is a DOM based Cross Site Scripting (XSS) vulnerability stemming from crafted URIs.
5
Can CVE-2017-15687 be exploited remotely?
Yes, CVE-2017-15687 can be exploited remotely through specially crafted URIs.