Stored XSS Vulnerability in Barco Control Room Management Suite Web Application
CVE-2022-26977
6.1MEDIUM
What is CVE-2022-26977?
The Barco Control Room Management Suite web application, specifically versions of TransForm N prior to 3.14, is vulnerable due to an insecure license file upload mechanism. This flaw arises from inadequate input sanitization, resulting in a stored cross-site scripting (XSS) vulnerability. Attackers may exploit this issue to inject malicious scripts into the application, potentially compromising user data and session integrity.