CVE-2017-12460: Barco Clickshare Csc-1 Firmware
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output.
Affected products
- Barco Clickshare Csc-1 Firmware: before 1.10.0.10 (fixed in 1.10.0.10)
- Barco Clickshare Csm-1 Firmware: before 1.7.0.3 (fixed in 1.7.0.3)
Published 2017-10-30. Last modified 2026-06-17.