QID 730755
Date Published: 2023-03-13
QID 730755: Grafana Stored Cross-Site Scripting (XSS) Vulnerability
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
CVE-2023-0507: Grafana's GeoMap core plugin had a stored XSS vulnerability due to unsanitized map attributions allowing arbitrary JavaScript execution. An Editor could inject JavaScript to escalate privileges and access an Admin's known password via a malicious dashboard. It's recommended to update Grafana and restrict Editor role access.
Affected Versions:
Grafana versions from 8.1.0 prior to 8.5.21
Grafana versions from 9.2.0 prior to 9.2.13
Grafana versions from 9.3.0 prior to 9.3.8
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Grafana from the server response
Successful exploitation of this vulnerability may allow an attacker with an Editor role to change to a known password for a user with an Admin role and, with the Admin role permissions, can execute malicious JavaScript viewing a dashboard.
- Grafana Security Advisory -
grafana.com/security/security-advisories/cve-2023-0507/
CVEs related to QID 730755
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Grafana Security Advisory |
|