CVE-2018-18625Cross-site Scripting in Grafana Grafana

CWE-79Cross-site Scripting10 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.8%
top 25.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateJun 28

Description

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Gogithub.com/grafana_grafana< 6.0.0-beta1+1
NVDgrafana/grafana5.3.1

Patches

🔴Vulnerability Details

5
OSV
Grafana XSS via adding a link in General feature in github.com/grafana/grafana2024-06-28
GHSA
Grafana XSS via adding a link in General feature2024-01-30
OSV
Grafana XSS via adding a link in General feature2024-01-30
OSV
CVE-2018-18625: Grafana 52020-06-02
CVEList
CVE-2018-18625: Grafana 52020-06-02

📋Vendor Advisories

1
Red Hat
grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen2020-06-02

💬Community

3
Bugzilla
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen2020-06-24
Bugzilla
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen [fedora-all]2020-06-24
Bugzilla
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen [fedora-all]2020-06-24
CVE-2018-18625 — Cross-site Scripting | cvebase