QID 150668
Date Published: 2023-04-17
QID 150668: Grafana Stored Cross Site Scripting Vulnerability (CVE-2023-1410)
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.
Affected Versions:
Grafana versions from 8.1.0 to 8.5.21
Grafana versions from 9.0.0 to 9.2.14
Grafana versions from 9.3.0 to 9.3.10
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a Grafana running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
CVEs related to QID 150668
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-1410 |
|