Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-12460 Details

Description

An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]

Affected Products

ProductVersions
barco clickshare csm-1 firmware
< 1.7.0.3

CPE

  • cpe:2.3:o:barco:clickshare_csm-1_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
barco clickshare csm-1
All versions

CPE

  • cpe:2.3:h:barco:clickshare_csm-1:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
barco clickshare csc-1 firmware
< 1.10.0.10

CPE

  • cpe:2.3:o:barco:clickshare_csc-1_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
barco clickshare csc-1
All versions

CPE

  • cpe:2.3:h:barco:clickshare_csc-1:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-12460
NVD Published Date:
Oct 30, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-12460 Details - Not Deferred