← Back to CVE List

CVE-2017-12460

Published: 2017-10-30T14:29Z
Last Modified: 2024-11-21T03:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt