HTML Injection Vulnerability in Barco ClickShare Products
CVE-2017-12460
5.4MEDIUM
What is CVE-2017-12460?
An HTML injection vulnerability exists in the Barco ClickShare CSM-1 and CSC-1 firmware prior to specified versions. Authenticated users can manipulate the wallpaper collection via the webUI, allowing for the upload of wallpapers with crafted names. This can result in the injection of HTML content, as special characters are not properly sanitized before being rendered, potentially leading to security risks for users interacting with affected systems.