Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-40004: CVE-2022-40004

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

CVE
#xss#vulnerability

### Description

a reflected XSS vulnerability allows users to elevate their privilege to admin

### Researcher

Saad Aldawsari (@aldawsari_saad)

### Vulnerability Type

Cross-Site-Scripting (XSS)

### Vendor of Product

Things Board

### Affected Product Code Base

Things Board < 3.4.1

### Affected Component

Audit Log

### Attack Type

Remote

### Impact Information Disclosure

True

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda