ZeroHour

CVE-2022-40004

CVSS 3.1
9.6 critical
EPSS
<1%p57
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

Vendors
thingsboard
Products
thingsboard
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.