CVE-2018-18624Cross-site Scripting in Grafana Grafana

Severity
6.1MEDIUMNVD
EPSS
0.6%
top 31.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateJun 28

Description

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

5
OSV
Grafana XSS via a column style in github.com/grafana/grafana2024-06-28
GHSA
Grafana XSS via a column style2022-05-24
OSV
Grafana XSS via a column style2022-05-24
CVEList
CVE-2018-18624: Grafana 52020-06-02
OSV
CVE-2018-18624: Grafana 52020-06-02

📋Vendor Advisories

1
Red Hat
grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen2020-06-02

💬Community

2
Bugzilla
CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen [fedora-all]2020-06-24
Bugzilla
CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen2020-06-24
CVE-2018-18624 — Cross-site Scripting | cvebase