VYPR
Unrated severityNVD Advisory· Published Oct 13, 2022· Updated May 15, 2025

CVE-2022-35134

CVE-2022-35134

Description

Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Boodskap IoT Platform v4.4.9-02 is vulnerable to stored cross-site scripting via unsanitized domain name and user name fields.

Vulnerability

Boodskap IoT Platform v4.4.9-02 contains a stored cross-site scripting (XSS) vulnerability due to insufficient input validation and output sanitization. Affected versions include v4.4.9-02. The vulnerability exists in multiple functionalities, including the domain name and user name fields [1].

Exploitation

An attacker can exploit the vulnerability by injecting a malicious script into the domain name field during configuration or by changing their user name to include a payload. For example, setting the domain name to `` results in script execution. A lower-privilege user can also change their own name to contain an XSS payload, potentially targeting an admin user when the admin views the user profile [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive data. The impact is limited by the same-origin policy but can be leveraged for further attacks against platform users [1].

Mitigation

As of the publication date, no official patch has been announced. The vendor has not released a fixed version. Users should implement strict input validation and output encoding, and consider using a Web Application Firewall (WAF) as a temporary workaround. Monitor the vendor for updates [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.