The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue. | |
| Title | Volkov Labs Business Links plugin vulnerable to privilege escalation attack | |
| Weaknesses | CWE-79 CWE-83 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-08T22:44:04.967Z
Updated: 2025-09-09T13:29:42.747Z
Reserved: 2025-09-04T19:18:09.498Z
Link: CVE-2025-58746
Updated: 2025-09-09T13:14:28.936Z
Status : Awaiting Analysis
Published: 2025-09-08T23:15:35.973
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-58746
No data.