Back to Database
Status published
Unknown
CVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows...
Vulnerability Description
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-40004
Credits & Attribution
No credits recorded in the NVD database.
More from thingsboard
View All →CVE-2025-34281
Stored Cross-Site Scripting (XSS) in ThingsBoard
Medium
6.2
CVE-2022-48341
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve...
High
8.8
CVE-2022-45608
An issue was discovered in ThingsBoard 3.4.1, allows low privileged...
High
8.8
CVE-2022-31861
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1...
Medium
5.4
CVE-2021-42751
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard...
Medium
4.8
Affected Vendor
thingsboard
View all reports →Affected Software
thingsboard
Vulnerable Versions:
3.4.1
Timeline
Official Publish:
December 15th, 2022
Last Modified:
April 21st, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.