FlawAtlas
Search the atlas
CVE-2020-12245 Moderate

Grafana XSS in header column rename

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

Exploit probability 1.9%
Published May 24, 2022
Required by Not available
Last source change June 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

48 explicit affected versions

Go github.com/grafana/grafana
Go github.com/grafana/grafana
Bitnami grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

View original source
Open Source Vulnerabilities GHSA-ccmg-w4xm-p28v

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

View original source
Open Source Vulnerabilities GO-2024-2517

Grafana XSS in header column rename in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v6.7.3.

View original source
Open Source Vulnerabilities BIT-grafana-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

View original source

05 / REFERENCES

Further evidence