CVE-2020-11110
18Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 9.6%
probabilidade de exploração
9.6%top 5% das CVEs
exploração observada
nãonenhuma fonte reporta
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
Produtos afetados
n/a · n/a