PT-2020-8637 · Grafana · Grafana

·

CVE-2018-18623

·

Published

2020-06-02

·

Updated

2024-08-21

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Grafana version 5.3.1
Description: The issue is related to an incomplete fix, resulting in a XSS vulnerability via the "Dashboard > Text Panel" screen. This allows for potential exploitation.
Recommendations: For Grafana version 5.3.1, consider disabling the Text Panel feature in the Dashboard as a temporary workaround until a patch is available. Restrict access to the Dashboard to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18623
ECHO-AB16-2279-8266
GHSA-CMQ2-J8V8-2Q44
GO-2022-0342
RHSA-2019:0019
SUSE-SU-2020:2876-1
SUSE-SU-2020:2911-1
SUSE-SU-2020:3309-1
SUSE-SU-2021:1233-1
SUSE-SU-2021:1962-1

Affected Products

Grafana