CVE-2022-26976: XSS
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26976?
CVE-2022-26976 is a vulnerability in the Barco Control Room Management Suite web application, part of TransForm N before version 3.14.1, that exposes a license file upload mechanism vulnerable to reflected XSS.
How does CVE-2022-26976 affect the Barco Control Room Management Suite web application?
CVE-2022-26976 affects the Barco Control Room Management Suite web application by exposing a license file upload mechanism that lacks input sanitization, allowing for reflected XSS attacks.
What is the severity of CVE-2022-26976?
The severity of CVE-2022-26976 is rated as medium, with a CVSS score of 5.4.
How can I fix CVE-2022-26976?
To fix CVE-2022-26976, it is recommended to update to version 3.14.1 or higher of the Barco Control Room Management Suite web application, part of TransForm N.
Where can I find more information about CVE-2022-26976?
More information about CVE-2022-26976 can be found on the Barco support knowledge base at https://www.barco.com/en/support/knowledge-base/KB12682 and https://www.barco.com/en/support/transform-n-management-server.