CVE-2021-42751: XSS
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42751 vulnerability?
CVE-2021-42751 is a cross-site scripting (XSS) vulnerability in the Rule Engine of ThingsBoard 3.3.1.
How does CVE-2021-42751 vulnerability affect ThingsBoard?
The vulnerability allows remote attackers with administrative access to inject arbitrary JavaScript within the description of a rule node in ThingsBoard 3.3.1.
What is the severity of CVE-2021-42751 vulnerability?
CVE-2021-42751 has a severity rating of 4.8, which is considered medium.
What can an attacker do with CVE-2021-42751 vulnerability?
An attacker with administrative access can inject arbitrary JavaScript code, potentially leading to unauthorized actions or data theft.
How can I fix CVE-2021-42751 vulnerability?
To fix the vulnerability, it is recommended to upgrade ThingsBoard to a version higher than 3.3.1, where the vulnerability has been patched.