CVE-2016-3150: XSS
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3150?
CVE-2016-3150 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-3150?
To fix CVE-2016-3150, upgrade the Barco ClickShare devices to firmware versions 01.09.03 or later for CSC-1, 01.06.02 or later for CSM-1, and 01.03.02 or later for CSE-200.
Which devices are affected by CVE-2016-3150?
CVE-2016-3150 affects Barco ClickShare CSC-1, CSM-1, and CSE-200 devices with specific firmware versions prior to the mentioned updates.
What can an attacker do with CVE-2016-3150?
An attacker exploiting CVE-2016-3150 can inject arbitrary web scripts or HTML, leading to potential unauthorized access or data manipulation.
Is there a workaround for CVE-2016-3150?
There are no specific workarounds for CVE-2016-3150; the best mitigations involve updating the firmware on affected devices.