CVE-2022-35134
Description
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Boodskap IoT Platform v4.4.9-02 is vulnerable to stored cross-site scripting via unsanitized domain name and user name fields.
Vulnerability
Boodskap IoT Platform v4.4.9-02 contains a stored cross-site scripting (XSS) vulnerability due to insufficient input validation and output sanitization. Affected versions include v4.4.9-02. The vulnerability exists in multiple functionalities, including the domain name and user name fields [1].
Exploitation
An attacker can exploit the vulnerability by injecting a malicious script into the domain name field during configuration or by changing their user name to include a payload. For example, setting the domain name to `` results in script execution. A lower-privilege user can also change their own name to contain an XSS payload, potentially targeting an admin user when the admin views the user profile [1].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive data. The impact is limited by the same-origin policy but can be leveraged for further attacks against platform users [1].
Mitigation
As of the publication date, no official patch has been announced. The vendor has not released a fixed version. Users should implement strict input validation and output encoding, and consider using a Web Application Firewall (WAF) as a temporary workaround. Monitor the vendor for updates [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Boodskap/IoT Platformdescription
- Range: =4.4.9-02
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.