First published: Wed Jun 01 2022(Updated: )
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco Control Room Management Suite | <3.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-26972.
The severity of CVE-2022-26972 is medium.
Barco Control Room Management Suite web application, which is part of TransForm N before version 3.14.1, is affected by CVE-2022-26972.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-26972 is CWE-79.
To fix CVE-2022-26972, it is recommended to upgrade to version 3.14.1 or later of Barco Control Room Management Suite.