MIRAGE
Threat IntelligenceCVEs › CVE-2020-11110

CVE-2020-11110 — exposed on the internet

Internet exposure observed by OffSeq scans · last 30 days

1
Exposed hosts
5.4
CVSS
9.6%
EPSS

Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2020-11110

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CWE-79

OffSeq internet scanning found CVE-2020-11110 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

grafana

Open the live CVE-2020-11110 view →

References