CVE-2017-12460: Barco Clickshare Csc-1 Firmware

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters are not neutralized before output.

Affected products

  • Barco Clickshare Csc-1 Firmware: before 1.10.0.10 (fixed in 1.10.0.10)
  • Barco Clickshare Csm-1 Firmware: before 1.7.0.3 (fixed in 1.7.0.3)

Published 2017-10-30. Last modified 2026-06-17.