PT-2022-18156 · Barco · Barco Control Room Management Suite

Published

2022-06-01

·

Updated

2022-06-09

·

CVE-2022-26978

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Barco Control Room Management Suite web application version prior to 3.14
Description The issue concerns the exposure of a URL "/checklogin.jsp" endpoint, where the os username parameter is not correctly sanitized. This leads to reflected XSS, allowing potential attackers to inject malicious scripts.
Recommendations For versions prior to 3.14, consider disabling access to the "/checklogin.jsp" endpoint until a patch is available. As a temporary workaround, restrict the use of the os username parameter in the affected endpoint to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26978

Affected Products

Barco Control Room Management Suite