First published: Wed Jun 01 2022(Updated: )
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco Control Room Management Suite | <3.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26976 is a vulnerability in the Barco Control Room Management Suite web application, part of TransForm N before version 3.14.1, that exposes a license file upload mechanism vulnerable to reflected XSS.
CVE-2022-26976 affects the Barco Control Room Management Suite web application by exposing a license file upload mechanism that lacks input sanitization, allowing for reflected XSS attacks.
The severity of CVE-2022-26976 is rated as medium, with a CVSS score of 5.4.
To fix CVE-2022-26976, it is recommended to update to version 3.14.1 or higher of the Barco Control Room Management Suite web application, part of TransForm N.
More information about CVE-2022-26976 can be found on the Barco support knowledge base at https://www.barco.com/en/support/knowledge-base/KB12682 and https://www.barco.com/en/support/transform-n-management-server.