VendorsBarcocontrol_room_management_suiteany version
Vulnerabilities

Barco Control Room Management Suite any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-26233
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
Published 2022-04-03 · Modified
7.5EPSS 0.150
CVE-2022-26975
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
Published 2022-06-01 · Modified
7.5EPSS 0.010
CVE-2022-26972
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
Published 2022-06-01 · Modified
6.1EPSS 0.006
CVE-2022-26974
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
Published 2022-06-01 · Modified
6.1EPSS 0.006
CVE-2022-26977
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
Published 2022-06-01 · Modified
6.1EPSS 0.006
CVE-2022-26978
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.
Published 2022-06-01 · Modified
6.1EPSS 0.006
CVE-2022-26976
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
Published 2022-06-01 · Modified
5.4EPSS 0.004
CVE-2022-26973
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
Published 2022-06-01 · Modified
5.3EPSS 0.008
CVE-2022-26971
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
Published 2022-06-01 · Modified
5.3EPSS 0.007