First published: Wed Jun 01 2022(Updated: )
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco Control Room Management Suite | <3.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-26973.
The severity of CVE-2022-26973 is medium with a score of 5.3.
Barco Control Room Management Suite web application, which is part of TransForm N before version 3.14.1, is affected by CVE-2022-26973.
Barco Control Room Management Suite web application is exposing a license file upload mechanism that exposes internal directory path details when the license file name is tweaked.
Please refer to the Barco support website for available fixes or patches for CVE-2022-26973.