CVE-2017-12460
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output.
Se ha descubierto un problema en Barco ClickShare con firmware CSM-1 anterior a v1.7.0.3 y firmware CSC-1 anterior a v1.10.0.10. Un usuario autenticado puede gestionar la colección de fondos de pantalla en la interfaz de usuario web para que se muestre como fondo en el producto ClickShare. Mediante la subida de un fondo de pantalla con un nombre especialmente manipulado, se puede desencadenar una inyección HTML, ya que los caracteres especiales no se neutralizan antes de la salida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-04 CVE Reserved
- 2017-10-30 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.barco.com/en/Support/software/R33050037 | 2017-11-18 | |
https://www.barco.com/en/support/knowledge-base/KB5169 | 2017-11-18 | |
https://www.barco.com/en/support/software/R33050020 | 2017-11-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barco Search vendor "Barco" | Clickshare Csm-1 Firmware Search vendor "Barco" for product "Clickshare Csm-1 Firmware" | < 1.7.0.3 Search vendor "Barco" for product "Clickshare Csm-1 Firmware" and version " < 1.7.0.3" | - |
Affected
| in | Barco Search vendor "Barco" | Clickshare Csm-1 Search vendor "Barco" for product "Clickshare Csm-1" | - | - |
Safe
|
Barco Search vendor "Barco" | Clickshare Csc-1 Firmware Search vendor "Barco" for product "Clickshare Csc-1 Firmware" | < 1.10.0.10 Search vendor "Barco" for product "Clickshare Csc-1 Firmware" and version " < 1.10.0.10" | - |
Affected
| in | Barco Search vendor "Barco" | Clickshare Csc-1 Search vendor "Barco" for product "Clickshare Csc-1" | - | - |
Safe
|