Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thingsboard thingsboard vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-45303
ThingsBoard prior to 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
Thingsboard Thingsboard
NA
CVE-2022-31861
Cross site Scripting (XSS) in ThingsBoard IoT Platform up to and including 3.3.4.1 via a crafted value being sent to the audit logs.
Thingsboard Thingsboard
605
VMScore
CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an malicious user to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happ...
Thingsboard Thingsboard
NA
CVE-2021-42750
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
Thingsboard Thingsboard 3.3.1
NA
CVE-2021-42751
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.
Thingsboard Thingsboard 3.3.1
NA
CVE-2022-48341
ThingsBoard 3.4.1 could allow a remote authenticated malicious user to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Thingsboard Thingsboard 3.4.1
NA
CVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote malicious users to escalate privilege via crafted URL to the Audit Log.
Thingsboard Thingsboard 3.4.1
NA
CVE-2022-45608
An issue exists in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker...
Thingsboard Thingsboard 3.4.1
NA
CVE-2023-26462
ThingsBoard 3.4.1 could allow a remote malicious user to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its sourc...
Thingsboard Thingsboard 3.4.1
NA
CVE-2024-3270
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to th...
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4654
CVE-2023-49606
encryption
NULL pointer dereference
CVE-2024-4439
CVE-2024-4649
race condition
CVE-2024-27202
CVE-2024-34566
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started