Stored Cross-Site Scripting Vulnerability in ThingsBoard Dashboard by ThingsBoard
CVE-2025-34281
6.2MEDIUM
What is CVE-2025-34281?
An XSS vulnerability exists in the ThingsBoard dashboard's Image Upload Gallery, where versions prior to 4.2.1 improperly handle SVG file uploads. By exploiting insufficient sanitization and validation of content types, an attacker can upload a malicious SVG file, allowing them to execute harmful JavaScript within the application's user interface. This vulnerability highlights critical security concerns regarding user-generated content and the importance of implementing strict validation measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
thingsboard 0 < 4.2.1
References
CVSS V4
Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tamil Mathi
