CVE-2023-0507 is a stored Cross-Site Scripting (XSS) vulnerability in Grafana's core GeoMap plugin, affecting versions starting from 8.1. This flaw allows an attacker with Editor role privileges to inject malicious JavaScript into map attributions, leading to arbitrary code execution in the context of other users. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to limited confidentiality and integrity impacts. While the EPSS and FAUCET Risk Score suggest a higher potential for exploitation, there is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.5.21CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 9.2.0, < 9.2.13CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.8CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grafana vulnerable to Cross-site Scripting
Mar 1, 2023grafana: cross site scripting
Mar 1, 2023XSS in Geomap in Grafana
Feb 28, 2023XSS in Geomap in Grafana
Feb 28, 2023XSS in Geomap in Grafana
Feb 28, 2023XSS in Geomap in Grafana
Feb 28, 2023XSS in Geomap in Grafana
Feb 28, 2023XSS in Geomap in Grafana
Feb 28, 2023