Vertical Privilege Escalation in ThingsBoard by ThingsBoard
CVE-2022-48341
8.8HIGH
What is CVE-2022-48341?
In ThingsBoard 3.4.1, a remote authenticated attacker can exploit a vulnerability to achieve vertical privilege escalation. This occurs when a Tenant Administrator modifies the scope parameter, thereby gaining unauthorized access to the System Administrator's dashboard. This flaw poses potential risks for data integrity and access control within the application.
