Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39495
HistoryMar 03, 2023 - 2:02 a.m.

Cross-site Scripting (XSS)

2023-03-0302:02:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
grafana
xss
vulnerability
admin
inject
javascript
change
password

0.001 Low

EPSS

Percentile

21.0%

github.com/grafana/grafana is vulnerable to Cross-site Scripting (XSS). The vulnerability exists because the value of a span’s attributes/resources is not properly sanitized, which allows an attacker with an admin role to inject and execute malicious JavaScript and change a password for a user when they have the editor role