CVE-2025-2703

Vulnerability Details

Basic Information

Title CVE-2025-2703
Type redhatcve
Published 2025-04-23T10:43:52
Last Seen 2025-04-23T11:12:12
CVSS Score 6.4 (MEDIUM)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required LOW
User Interaction NONE
Scope CHANGED
Confidentiality Impact LOW
Integrity Impact LOW
Availability Impact NONE

CVE Information

CVE IDs CVE-2025-2703
CWE
Bulletin Family info

Description

A DOM-based Cross-site scripting vulnerability exists in Grafana’s built-in XY Chart plugin. This flaw allows an attacker with editor-level privileges to inject and execute arbitrary JavaScript code by editing an XY Chart Panel. The vulnerability bypasses the Content Security Policy, allowing the script to execute when the chart is rendered.
#### Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Impact Assessment

Base Score 6.4
Severity MEDIUM

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.