Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thingsboard thingsboard vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-45303
ThingsBoard prior to 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
Thingsboard Thingsboard
NA
CVE-2022-31861
Cross site Scripting (XSS) in ThingsBoard IoT Platform up to and including 3.3.4.1 via a crafted value being sent to the audit logs.
Thingsboard Thingsboard
6.8
CVSSv2
CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an malicious user to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happ...
Thingsboard Thingsboard
NA
CVE-2022-48341
ThingsBoard 3.4.1 could allow a remote authenticated malicious user to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Thingsboard Thingsboard 3.4.1
NA
CVE-2021-42750
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
Thingsboard Thingsboard 3.3.1
NA
CVE-2021-42751
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.
Thingsboard Thingsboard 3.3.1
NA
CVE-2022-45608
An issue exists in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker...
Thingsboard Thingsboard 3.4.1
NA
CVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote malicious users to escalate privilege via crafted URL to the Audit Log.
Thingsboard Thingsboard 3.4.1
NA
CVE-2023-26462
ThingsBoard 3.4.1 could allow a remote malicious user to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its sourc...
Thingsboard Thingsboard 3.4.1
NA
CVE-2024-3270
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to th...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started