CVE-2022-26978

Publication date

2022-06-01 11:35:22

Family

mitre

State

PUBLISHED

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.