CVE-2019-13068
MEDIUM5.4EPSS 4.8%Grafana Cross-site Scripting vulnerability
Published: 5/24/2022Modified: 11/8/2023
Description
`public/app/features/panel/panel_ctrl.ts` in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Affected packages (1)
- Go/github.com/grafana/grafanafrom 0, < 6.2.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-13068
- PATCHhttps://github.com/grafana/grafana
- WEBhttp://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- WEBhttps://github.com/grafana/grafana/issues/17718
- WEBhttps://github.com/grafana/grafana/releases/tag/v6.2.5
- WEBhttps://security.netapp.com/advisory/ntap-20190710-0001