Vulnerabilidad · Publicado 22/06/2026 · Actualizado 01/08/2026
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Modified
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Grafana — Grafana
CWE-79
Publicado en NIST NVD.