CVE-2017-12460: XSS
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12460?
The severity of CVE-2017-12460 is medium, with a severity value of 5.4.
How can an authenticated user manage the wallpaper collection in the webUI for the affected Barco ClickShare products?
An authenticated user can manage the wallpaper collection in the webUI for the affected Barco ClickShare products by uploading a wallpaper with a specially crafted name.
What is the impact of CVE-2017-12460?
CVE-2017-12460 allows an authenticated user to upload a specially crafted wallpaper, potentially leading to unauthorized access or privilege escalation.
How can I check if my Barco ClickShare CSM-1 firmware is affected?
You can check if your Barco ClickShare CSM-1 firmware is affected by verifying that the version is earlier than v1.7.0.3.
How can I check if my Barco Clickshare Csc-1 Firmware is affected?
You can check if your Barco Clickshare Csc-1 Firmware is affected by verifying that the version is earlier than v1.10.0.10.