Junglewise Threat Intelligence

CVE-2016-3150: Barco ClickShare XSS in wallpaper.php

CVE-2016-3150 · Severity: medium · CVSS 6.1 · Published 2017-01-12

Technologies: Barco Clickshare Csc-1, Barco Clickshare Csc-1 Firmware. Vendors: Barco.

Executive brief

Barco ClickShare is a wireless presentation system used in meeting rooms to share content from laptops to a central screen. A security flaw in the device's management interface allows an attacker to inject malicious scripts into the web browser of a user who visits a crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the 'wallpaper.php' script within the web-based management interface of several Barco ClickShare Base Unit models. The vulnerability is caused by insufficient sanitization of user-supplied input, allowing a remote, unauthenticated attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a user to interact with a malicious link or visit a compromised website while authenticated to the ClickShare device. Successful exploitation can lead to session hijacking or unauthorized configuration changes. The issue is resolved in firmware versions 01.09.03 (CSC-1), 01.06.02 (CSM-1), and 01.03.02 (CSE-200).

Affected products

  • Barco ClickShare CSC-1 Base Unit before 01.09.03
  • Barco ClickShare CSM-1 Base Unit before 01.06.02
  • Barco ClickShare CSE-200 Base Unit before 01.03.02

Timeline

  • 2016-03-10: disclosed: CVE reserved date
  • 2017-01-12: advisory: NVD publication date

References

Related threats