CVE-2022-26978: XSS
Published Jun 1, 2022
·Updated
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The osusername parameters is not correctly sanitized, leading to reflected XSS.
Affected Software
1 affected component
Barco Control Room Management Suite<3.14.1
Event History
Jun 1, 2022
CVE Published
via MITRE·11:35 AM
Data Sourced
via MITRE·11:35 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of Barco Control Room Management Suite?
The vulnerability ID is CVE-2022-26978.
2
What is the severity of CVE-2022-26978?
The severity of CVE-2022-26978 is medium.
3
What is the affected software of CVE-2022-26978?
The affected software is Barco Control Room Management Suite before version 3.14.1.
4
What is the description of CVE-2022-26978?
CVE-2022-26978 is a vulnerability in Barco Control Room Management Suite web application that exposes a URL /checklogin.jsp endpoint allowing for reflected XSS due to incorrect sanitization of the os_username parameter.
5
How can CVE-2022-26978 be fixed?
To fix CVE-2022-26978, it is recommended to update Barco Control Room Management Suite to version 3.14.1 or later.