Metrics
Affected Vendors & Products
Tue, 16 Dec 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files. | ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. |
| Title | ThingsBoard < v4.2.1 SVG Image Stored XSS | Stored Cross-Site Scripting (XSS) in ThingsBoard |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 24 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thingsboard
Thingsboard thingsboard |
|
| Vendors & Products |
Thingsboard
Thingsboard thingsboard |
Fri, 17 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files. | |
| Title | ThingsBoard < v4.2.1 SVG Image Stored XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-16T10:59:45.612Z
Reserved: 2025-04-15T19:15:22.581Z
Link: CVE-2025-34281
Updated: 2025-10-17T18:59:48.159Z
Status : Modified
Published: 2025-10-17T19:15:37.197
Modified: 2025-12-16T11:15:43.777
Link: CVE-2025-34281
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:21:53Z