Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37247
HistorySep 23, 2022 - 7:31 a.m.

Privilege Escalation

2022-09-2307:31:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
40
grafana
cross-site scripting
privilege escalation
unauthorized actions
vulnerability

EPSS

0.001

Percentile

22.7%

github.com/grafana/grafana is vulnerable to cross-site scripting. The vulnerability exists in multiple functions of dashboard_permissions.go because viewer and editor permissions to dashboards and folders are not properly controlled with admin permissions which allows an attacker to gain access and perform unauthorized actions on them.