Vulnerability record · CVE-2019-13068 · published 30 June 2019
CVE-2019-13068: Grafana panel drilldown links allow HTML injection
Grafana · Grafana
Grafana before 6.2.5 fails to sanitize the Title or url fields of panel drilldown links, allowing HTML injection in public/app/features/panel/panel_ctrl.ts. Because the injected content renders in the Grafana UI, it can be used to alter or spoof what other users see.
Description
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) with user interaction required, but the high EPSS score and public advisory raise the likelihood of attempted exploitation.
What it is
Grafana before 6.2.5 fails to sanitize the Title or url fields of panel drilldown links, allowing HTML injection in public/app/features/panel/panel_ctrl.ts. Because the injected content renders in the Grafana UI, it can be used to alter or spoof what other users see.
Impact
An attacker can inject arbitrary HTML into drilldown links, enabling content spoofing or script-driven actions in the victim's browser session. The CVSS vector limits this to low confidentiality and integrity impact with no availability effect.
Attack surface
Reached over the network through the Grafana web interface; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must view or click the crafted drilldown link.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.52 (98.9th percentile), and a public Packet Storm advisory exists; no confirmed in-the-wild exploitation is stated in the record.
What to do
- Upgrade Grafana to 6.2.5 or later, which contains the fix.
- If immediate upgrade is not possible, restrict who can create or edit panels and drilldown links.
- Sanitize or encode the Title and url fields of drilldown links before rendering.
- Review dashboards for unexpected or externally supplied drilldown link content.
Detection
- Search Grafana logs and audit trails for panel or dashboard edits that add unusual HTML in drilldown link Title or url fields.
- Inspect rendered dashboards for injected markup or unexpected script content in drilldown links.
- Monitor for requests to Grafana versions below 6.2.5 from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html | |
| https://github.com/grafana/grafana/issues/17718 | Third Party Advisory |
| https://github.com/grafana/grafana/releases/tag/v6.2.5 | Release NotesThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20190710-0001/ | |
| http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html | |
| https://github.com/grafana/grafana/issues/17718 | Third Party Advisory |
| https://github.com/grafana/grafana/releases/tag/v6.2.5 | Release NotesThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20190710-0001/ |
Track CVE-2019-13068 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-13068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.