CVE-2022-26972

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/06/2022
Last modified:
09/06/2022

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:barco:control_room_management_suite:*:*:*:*:*:*:*:* 3.14.1 (excluding)