← Vulnerability feed

Vulnerability record · CVE-2016-3150 · published 12 January 2017

CVE-2016-3150: Barco clickshare csc-1 firmware cross-site scripting vulnerability

BBarco · Clickshare Csc 1 Firmware

Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6.1 CVSS 3.0 Medium EPSS 1.3% · top 31.3% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18830Barco clickshare cs-100 firmware os command injection vulnerabilityBarco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the function…EPSS 4.3%9.8CVE-2019-18826Barco clickshare cs-100 firmware improper certificate validation vulnerabilityBarco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' prog…EPSS 0.68%9.8CVE-2016-3149Barco clickshare csc-1 firmware vulnerabilityBarco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitr…EPSS 7.8%9.8CVE-2016-3152Barco clickshare csc-1 firmware information exposure vulnerabilityBarco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the fir…EPSS 2.8%8.8CVE-2017-9377Barco clickshare csm-1 firmware os command injection vulnerabilityA command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An a…EPSS 4.3%7.5CVE-2019-18825Barco clickshare cs-100 huddle firmware vulnerabilityBarco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Base Unit …EPSS 0.60%7.5CVE-2018-10943Barco clickshare cse-200 firmware improper input validation vulnerabilityAn issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP…EPSS 1.1%7.5CVE-2016-3151Barco clickshare csc-1 firmware path traversal vulnerabilityDirectory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devic…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2016-3150), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.