Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37980
HistoryNov 11, 2022 - 4:12 a.m.

Privilege Escalation

2022-11-1104:12:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
privilege escalation
email validation
admins
user registration
software security

0.002 Low

EPSS

Percentile

53.0%

github.com/grafana/grafana is vulnerable to privilege escalation due to improper email validation in the response parameter of org_invite.go. Admins can create new users with a registration link sent via email, allowing an attacker to register a user on the site with a different email address used than the one used for sending the registration link.