Thingsboard

Thingsboard

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.86%
  • Veröffentlicht 06.10.2023 19:15:13
  • Zuletzt bearbeitet 21.11.2024 08:26:43

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

  • EPSS 0.91%
  • Veröffentlicht 01.03.2023 16:15:09
  • Zuletzt bearbeitet 07.03.2025 18:15:36

An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in ...

  • EPSS 1.13%
  • Veröffentlicht 23.02.2023 06:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:32

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the applica...

  • EPSS 0.99%
  • Veröffentlicht 23.02.2023 06:15:10
  • Zuletzt bearbeitet 12.03.2025 15:15:37

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.

  • EPSS 0.87%
  • Veröffentlicht 15.12.2022 23:15:10
  • Zuletzt bearbeitet 21.04.2025 18:15:17

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 13.09.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:24

Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

Exploit
  • EPSS 2.33%
  • Veröffentlicht 12.08.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:05

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.

Exploit
  • EPSS 2.33%
  • Veröffentlicht 12.08.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:05

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.

Exploit
  • EPSS 1.52%
  • Veröffentlicht 18.12.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:21:39

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host he...