Privilege Escalation Vulnerability in Volkov Labs Business Links for Grafana
CVE-2025-58746
9.1CRITICAL
What is CVE-2025-58746?
The Volkov Labs Business Links plugin for Grafana has a vulnerability where users with Editor privileges can escalate their access to Administrator levels. This security flaw arises from the ability to inject arbitrary JavaScript code in the plugin’s URL field, allowing malicious actors to perform unauthorized administrative actions. The issue has been addressed in version 2.4.0, which includes a fix for the vulnerability, ensuring enhanced security for Grafana users.
Affected Version(s)
business-links < 2.4.0