ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thingsboard
Thingsboard thingsboard |
|
| Vendors & Products |
Thingsboard
Thingsboard thingsboard |
Fri, 17 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files. | |
| Title | ThingsBoard < v4.2.1 SVG Image Stored XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-10-17T18:33:03.941Z
Updated: 2025-10-17T18:59:51.297Z
Reserved: 2025-04-15T19:15:22.581Z
Link: CVE-2025-34281
Updated: 2025-10-17T18:59:48.159Z
Status : Analyzed
Published: 2025-10-17T19:15:37.197
Modified: 2025-10-24T13:27:01.183
Link: CVE-2025-34281
No data.