PT-2025-36525 · Volkov+1 · Business Links Panel For Grafana+1

Kazeruch

·

Published

2025-09-08

·

Updated

2025-09-11

·

CVE-2025-58746

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Volkov Labs Business Links panel for Grafana versions prior to 2.4.0
Description: The Volkov Labs Business Links panel for Grafana allows navigation using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible due to arbitrary JavaScript code injection in the URL field within the [Layout] → [Link] → [URL] configuration.
Recommendations: Update to version 2.4.0 or later.

Exploit

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-58746
GHSA-93QJ-GV4P-MF53

Affected Products

Business Links Panel For Grafana
Grafana