Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39087
HistoryFeb 02, 2023 - 11:20 a.m.

Cross Site Scripting (XSS)

2023-02-0211:20:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
cross site scripting
grafana
software
vulnerability
svg files

EPSS

0.001

Percentile

45.4%

github.com/grafana/grafana is vulnerable to Cross Site Scripting (XSS) attacks. The vulnerability exists due to svg files not being sanitized properly allowing an attacker to execute arbitrary JavaScript in the context of an authorized user.