Impact
A user with Editor permissions can create a that is stored and later executed as script code in the browsers of any user who views the dashboard. This stored cross‑site scripting flaw (CWE‑79) allows client‑side code to run with the privileges of the viewing user, potentially enabling a range of browser‑based attacks such as data exfiltration, UI manipulation or execution of additional payloads.
Affected Systems
All installations of Grafana OSS that incorporate the TableNG panel component are potentially affected. The advisory does not specify a fixed release or list unaffected versions, so any deployment of the affected panel is at risk unless a patched version is in use.
Risk and Exploitability
The CVSS base score of 6.8 reflects moderate severity. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The attack requires an authenticated Editor to craft or modify a dashboard containing the malicious field name; an attacker therefore needs either legitimate editing rights, or must compromise or coerce an user with such rights. Once the dashboard is published, any viewer will load the stored script in their browser.
OpenCVE Enrichment