CVE-2022-26972: XSS
Published Jun 1, 2022
·Updated
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
Affected Software
1 affected component
Barco Control Room Management Suite<3.14.1
Event History
Jun 1, 2022
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-26972.
2
What is the severity of CVE-2022-26972?
The severity of CVE-2022-26972 is medium.
3
What software is affected by CVE-2022-26972?
Barco Control Room Management Suite web application, which is part of TransForm N before version 3.14.1, is affected by CVE-2022-26972.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-26972?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-26972 is CWE-79.
5
How can I fix CVE-2022-26972?
To fix CVE-2022-26972, it is recommended to upgrade to version 3.14.1 or later of Barco Control Room Management Suite.