Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Torkeloop

#47338of 53,608
5.4Total CVSS
Vulnerabilities · 1
PT-2019-13106
5.4
2019-06-29
Grafana · Grafana · CVE-2019-13068
**Name of the Vulnerable Software and Affected Versions** Grafana versions prior to 6.2.5 **Description** The issue allows HTML Injection in panel drilldown links via the Title or url field. This is related to the `public/app/features/panel/panel ctrl.ts` file in Grafana. **Recommendations** For versions prior to 6.2.5, update to version 6.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Title and url fields in panel drilldown links to minimize the risk of exploitation.