Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thingsboard thingsboard vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-45303
ThingsBoard prior to 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
Thingsboard Thingsboard
8.8
CVSSv3
CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an malicious user to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happ...
Thingsboard Thingsboard
5.4
CVSSv3
CVE-2022-31861
Cross site Scripting (XSS) in ThingsBoard IoT Platform up to and including 3.3.4.1 via a crafted value being sent to the audit logs.
Thingsboard Thingsboard
4.8
CVSSv3
CVE-2021-42750
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
Thingsboard Thingsboard 3.3.1
4.8
CVSSv3
CVE-2021-42751
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.
Thingsboard Thingsboard 3.3.1
9.6
CVSSv3
CVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote malicious users to escalate privilege via crafted URL to the Audit Log.
Thingsboard Thingsboard 3.4.1
8.1
CVSSv3
CVE-2023-26462
ThingsBoard 3.4.1 could allow a remote malicious user to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its sourc...
Thingsboard Thingsboard 3.4.1
8.8
CVSSv3
CVE-2022-48341
ThingsBoard 3.4.1 could allow a remote authenticated malicious user to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Thingsboard Thingsboard 3.4.1
8.8
CVSSv3
CVE-2022-45608
An issue exists in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker...
Thingsboard Thingsboard 3.4.1
NA
CVE-2024-3270
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to th...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started