CVE-2018-18625: XSS
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-18625?
CVE-2018-18625 is a vulnerability in Grafana 5.3.1 that allows for cross-site scripting (XSS) via a link on the Dashboard > All Panels > General screen.
What is the severity of CVE-2018-18625?
CVE-2018-18625 has a severity level of medium.
How does CVE-2018-18625 affect Grafana?
CVE-2018-18625 affects Grafana 5.3.1 and allows for XSS attacks through a link on the Dashboard > All Panels > General screen.
How can I fix the CVE-2018-18625 vulnerability?
To fix the CVE-2018-18625 vulnerability, you should update Grafana to the latest version and apply any patches or security updates provided by the vendor.
Where can I find more information about CVE-2018-18625?
You can find more information about CVE-2018-18625 at the following references: [Link 1](https://github.com/grafana/grafana/pull/11813), [Link 2](https://security.netapp.com/advisory/ntap-20200608-0008/).