8.8
CVSSv3

CVE-2023-45303

Published: 06/10/2023 Updated: 12/10/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

ThingsBoard prior to 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

Vulnerable Product Search on Vulmon Subscribe to Product

thingsboard thingsboard