Confirms that Grafana's XY Chart plugin renders tooltip content using innerHTML without sanitization. An attacker with editor access can craft a dashboard link that executes JavaScript in any viewer's browser, stealing session tokens.
Is your app exploitable through CVE-2025-2703?
Scan your domain free