CVE-2017-16567 is a persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, specifically within its "Favorites" feature. This allows remote attackers to inject and store malicious JavaScript, which executes when users access the compromised functionality. Rated Medium severity (CVSS 5.4), exploitation can lead to session hijacking, credential theft, unauthorized actions, and data exfiltration, requiring user interaction but with low attack complexity. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, an ExploitDB proof-of-concept (EDB-43122) exists, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.9.0CPE matchmatch criteria | cpe:2.3:a:logitech:media_server:7.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.