Description
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Remediation
References
Related Vulnerabilities
Magento Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2019-8154)
ATutor Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3368)
Roundcube Improper Privilege Management Vulnerability (CVE-2017-8114)
MySQL CVE-2012-0583 Vulnerability (CVE-2012-0583)
Liferay DXP Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-15839)