First published: Sat Jun 29 2019(Updated: )
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Labs Grafana OSS and Enterprise | <6.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-13068 is classified as medium due to its potential for HTML injection which can affect user interaction.
To fix CVE-2019-13068, upgrade Grafana to version 6.2.5 or later.
CVE-2019-13068 can lead to attacks involving HTML injection, which may allow an attacker to manipulate or mislead users.
CVE-2019-13068 affects all versions of Grafana prior to 6.2.5.
CVE-2019-13068 involves the panel drilldown links within the panel_ctrl.ts component in Grafana.