Security Advisory

CVE-2022-26978

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-01 11:35:22
Last updated 2024-08-03 05:18:39
Assigner mitre
State PUBLISHED

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.