Deferred
Published: 23 Apr 2025, 11:36
Last modified:10 Jun 2025, 10:53

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.04% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Apr 2025, 11:36
Published
Vulnerability first disclosed
10 Jun 2025, 10:53
Last Modified
Vulnerability information updated

Description

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

CVSS Metrics

  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

EPSS Trends

Current EPSS score: 0.04% Percentile: 13%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • grafanagrafana

    ≥ 11.6.0, < 11.6.0+security-01 | ≥ 11.5.0, < 11.5.3+security-01 | ≥ 11.4.0, < 11.4.3+security-01 | ≥ 11.3.0, < 11.3.5+security-01 | ≥ 11.2.0, < 11.2.8+security-01

  • grafanagrafana enterprise

    ≥ 11.6.0, < 11.6.0+security-01 | ≥ 11.5.0, < 11.5.3+security-01 | ≥ 11.4.0, < 11.4.3+security-01 | ≥ 11.3.0, < 11.3.5+security-01 | ≥ 11.2.0, < 11.2.8+security-01

References (2)