CVE-2022-31861: XSS
Published Sep 13, 2022
·Updated
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
Affected Software
1 affected component
ThingsBoard ThingsBoard<=3.3.4.1
Event History
Sep 13, 2022
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31861?
The severity of CVE-2022-31861 is medium.
2
How does CVE-2022-31861 affect ThingsBoard IoT Platform?
CVE-2022-31861 affects ThingsBoard IoT Platform versions up to and including 3.3.4.1.
3
What is the CWE ID for CVE-2022-31861?
The CWE ID for CVE-2022-31861 is 79.
4
What is Cross-Site Scripting (XSS)?
Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
How do I fix the Cross-Site Scripting (XSS) vulnerability in ThingsBoard IoT Platform?
To fix the Cross-Site Scripting (XSS) vulnerability in ThingsBoard IoT Platform, it is recommended to upgrade to a version higher than 3.3.4.1.