Vulnerabilities (CVE)

Filtered by vendor Barco Subscribe
Filtered by product Control Room Management Suite
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26971 1 Barco 1 Control Room Management Suite 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
CVE-2022-26972 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
CVE-2022-26973 1 Barco 1 Control Room Management Suite 2022-06-09 5.0 MEDIUM 5.3 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
CVE-2022-26974 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
CVE-2022-26976 1 Barco 1 Control Room Management Suite 2022-06-09 3.5 LOW 5.4 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
CVE-2022-26977 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
CVE-2022-26978 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.