Reflected XSS Vulnerability in Barco TransForm N Control Room Management Suite
CVE-2022-26978

6.1MEDIUM

Key Information:

Vendor

Barco

Vendor
CVE Published:
2 June 2022

What is CVE-2022-26978?

The Barco TransForm N Control Room Management Suite has a security flaw in its '/checklogin.jsp' endpoint, where the 'os_username' parameter is inadequately sanitized. This vulnerability allows attackers to inject malicious scripts that could be executed in the context of the user's browser session, potentially leading to unauthorized access and data leakage. Organizations using versions prior to 3.14 should take immediate steps to mitigate this issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.