CVE-2017-17750: XSS
Published Mar 24, 2018
·Updated
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
Affected Software
2 affected components
Bose Soundtouch Android
Bose Soundtouch Iphone Os
Event History
Mar 24, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17750?
CVE-2017-17750 is classified as a high severity vulnerability due to the potential for exploitation via cross-site scripting.
2
How do I fix CVE-2017-17750?
To mitigate CVE-2017-17750, users should update their Bose SoundTouch application to the latest version that addresses this XSS vulnerability.
3
What type of devices are affected by CVE-2017-17750?
CVE-2017-17750 affects Bose SoundTouch devices running on Android and iOS operating systems.
4
What kind of attack can be executed through CVE-2017-17750?
CVE-2017-17750 allows attackers to execute cross-site scripting (XSS) attacks using crafted public playlists from Spotify.
5
Is user data at risk due to CVE-2017-17750?
Yes, user data may be at risk as an attacker could execute malicious scripts that compromise user privacy and security.