Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2020-11110Cross-site Scripting in Grafana Grafana

Severity
5.4MEDIUMNVD
EPSS
54.0%
top 1.98%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 27
Latest updateJun 28

Description

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

5
OSV
Grafana stored XSS in github.com/grafana/grafana2024-06-28
GHSA
Grafana stored XSS2022-05-24
OSV
Grafana stored XSS2022-05-24
OSV
CVE-2020-11110: Grafana through 62020-07-27
CVEList
CVE-2020-11110: Grafana through 62020-07-27

💥Exploits & PoCs

1
Nuclei
Grafana <= 6.7.1 - Cross-Site Scripting

📋Vendor Advisories

1
Red Hat
grafana: stored XSS2020-04-01

💬Community

1
Bugzilla
CVE-2020-11110 grafana: stored XSS2020-07-27
CVE-2020-11110 — Cross-site Scripting | cvebase