HTML Injection Vulnerability in Barco ClickShare Products
CVE-2017-12460

5.4MEDIUM

Key Information:

Vendor

Barco

Vendor
CVE Published:
30 October 2017

What is CVE-2017-12460?

An HTML injection vulnerability exists in the Barco ClickShare CSM-1 and CSC-1 firmware prior to specified versions. Authenticated users can manipulate the wallpaper collection via the webUI, allowing for the upload of wallpapers with crafted names. This can result in the injection of HTML content, as special characters are not properly sanitized before being rendered, potentially leading to security risks for users interacting with affected systems.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-12460 : HTML Injection Vulnerability in Barco ClickShare Products