← Back to CVE List

CVE-2020-11110

Published: 2020-07-27T13:15Z
Last Modified: 2024-11-21T04:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt