CVE-2022-40004: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.
Affected Software
1 affected component
ThingsBoard ThingsBoard=3.4.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40004?
The severity of CVE-2022-40004 is critical with a CVSS score of 9.6.
2
How does the Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 impact the system?
The vulnerability allows remote attackers to escalate privilege by exploiting a crafted URL to the Audit Log.
3
Which software versions are affected by CVE-2022-40004?
The vulnerability affects Things Board 3.4.1.
4
Is there a fix available for the Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1?
A fix may be available from the software vendor. It is recommended to update to the latest version or apply the vendor-provided patch.
5
Where can I find more information about CVE-2022-40004?
More information about CVE-2022-40004 can be found at the following link: [https://gist.github.com/s3d113/bba63da007fcbe243615dd2a81690ffb]