Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5716 | Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted.. |
Github GHSA |
GHSA-x5fh-fvvr-892f | Grafana XSS Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:31:53.978Z
Reserved: 2018-12-20T00:00:00Z
Link: CVE-2018-1000816
No data.
Status : Modified
Published: 2018-12-20T15:29:00.643
Modified: 2024-11-21T03:40:25.107
Link: CVE-2018-1000816
OpenCVE Enrichment
No data.
EUVD
Github GHSA