Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://www.barco.com/en/support/transform-n-management-server | product vendor advisory |
https://www.barco.com/en/support/knowledge-base/KB12678 | vendor advisory |