Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39149
HistoryFeb 07, 2023 - 5:46 a.m.

Cross-Site Scripting (XSS)

2023-02-0705:46:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
102
cross-site scripting
xss
grafana
vulnerability
user inputs
javascript execution

0.001 Low

EPSS

Percentile

50.9%

github.com/grafana/grafana is vulnerable to Cross-Site Scripting (XSS). The vulnerability exists due to improper sanitization of user inputs in the originalUrl parameter which allows an attacker to inject and execute arbitrary JavaScript.