6.1
CVSSv3

CVE-2016-1000220

Published: 16/06/2017 Updated: 14/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Kibana prior to 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an malicious user to execute arbitrary JavaScript in users' browsers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Vendor Advisories

A cross-site scripting (XSS) flaw was found in Kibana A remote attacker could use this flaw to inject arbitrary web script into pages served to other users ...