CVE-2022-26973

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/06/2022
Last modified:
09/06/2022

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:barco:control_room_management_suite:*:*:*:*:*:*:*:* 3.14.1 (excluding)