Vulnerability Description
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thingsboard | Thingsboard | 3.3.1 |
Related Weaknesses (CWE)
References
- https://github.com/thingsboard/thingsboardProductThird Party Advisory
- https://packetstormsecurity.com/files/167999/Thingsboard-3.3.1-Cross-Site-ScriptExploitThird Party AdvisoryVDB Entry
- https://github.com/thingsboard/thingsboardProductThird Party Advisory
- https://packetstormsecurity.com/files/167999/Thingsboard-3.3.1-Cross-Site-ScriptExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2021-42750?
CVE-2021-42750 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.
How severe is CVE-2021-42750?
CVE-2021-42750 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42750?
Check the references section above for vendor advisories and patch information. Affected products include: Thingsboard Thingsboard.