CVE-2022-26974

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/06/2022
Last modified:
09/06/2022

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:barco:control_room_management_suite:*:*:*:*:*:*:*:* 3.14.1 (excluding)