Vulnerabilities
Vulnerable Software
Thingsboard:  >> Thingsboard  Security Vulnerabilities
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source code.)
CVSS Score
8.1
EPSS Score
0.007
Published
2023-02-23
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.
CVSS Score
9.6
EPSS Score
0.003
Published
2022-12-15
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
CVSS Score
5.4
EPSS Score
0.003
Published
2022-09-13
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
CVSS Score
4.8
EPSS Score
0.007
Published
2022-08-12
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.
CVSS Score
4.8
EPSS Score
0.007
Published
2022-08-12
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-12-18


Contact Us

Shodan ® - All rights reserved