Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39497
HistoryMar 03, 2023 - 3:42 a.m.

Cross-site Scripting (XSS)

2023-03-0303:42:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
cross-site scripting
react render cycle
text plugin
unsantized html
malicious javascript
admin account

0.002 Low

EPSS

Percentile

64.5%

github.com/grafana/grafana is vulnerable to Cross-site Scripting (XSS). The vulnerability exists due to React’s render cycle in the “Text” plugin which passes through the unsanitized HTML code, allowing an attacker with an editor role to inject and execute malicious JavaScript, and take over the admin account if they click the “Markdown” or “HTML” text panel.