PT-2025-36525 · Volkov+1 · Business Links Panel For Grafana+1
Kazeruch
·
Published
2025-09-08
·
Updated
2025-09-11
·
CVE-2025-58746
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Volkov Labs Business Links panel for Grafana versions prior to 2.4.0
Description:
The Volkov Labs Business Links panel for Grafana allows navigation using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible due to arbitrary JavaScript code injection in the
URL field within the [Layout] → [Link] → [URL] configuration.Recommendations:
Update to version 2.4.0 or later.
Exploit
Fix
LPE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Business Links Panel For Grafana
Grafana