Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39498
HistoryMar 03, 2023 - 4:39 a.m.

Stored Cross-site Scripting (XSS)

2023-03-0304:39:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
43
cross-site scripting
github.com/grafana/grafana
geomap plugin
javascript
admin user
password

0.001 Low

EPSS

Percentile

29.6%

github.com/grafana/grafana is vulnerable to Cross-site Scripting (XSS). The vulnerability exists due to map attributes in the Geomap plugin which library does not properly sanitize, allowing an attacker with an editor role to inject and execute malicious JavaScript. If an admin user clicks on the map panel, the attacker can change the password.