Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

github логотип

GHSA-q53q-gxq9-mgrj

около 1 года назад

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
EPSS: Критический
ubuntu логотип

CVE-2025-4123

около 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
redhat логотип

CVE-2025-4123

около 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
nvd логотип

CVE-2025-4123

около 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
debian логотип

CVE-2025-4123

около 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
EPSS: Критический
rocky логотип

RLSA-2025:7894

около 1 года назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7893

10 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7892

10 месяцев назад

Important: grafana security update

EPSS: Критический
oracle-oval логотип

ELSA-2025-7894

около 1 года назад

ELSA-2025-7894: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7893

около 1 года назад

ELSA-2025-7893: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7892

около 1 года назад

ELSA-2025-7892: grafana security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-06809

около 1 года назад

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
EPSS: Критический
redos логотип

ROS-20250619-15

около 1 года назад

Множественные уязвимости grafana

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20654-1

3 месяца назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q53q-gxq9-mgrj

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
98%
Критический
около 1 года назад
ubuntu логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
98%
Критический
около 1 года назад
redhat логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
98%
Критический
около 1 года назад
nvd логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
98%
Критический
около 1 года назад
debian логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
98%
Критический
около 1 года назад
rocky логотип
RLSA-2025:7894

Important: grafana security update

98%
Критический
около 1 года назад
rocky логотип
RLSA-2025:7893

Important: grafana security update

98%
Критический
10 месяцев назад
rocky логотип
RLSA-2025:7892

Important: grafana security update

98%
Критический
10 месяцев назад
oracle-oval логотип
ELSA-2025-7894

ELSA-2025-7894: grafana security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-7893

ELSA-2025-7893: grafana security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-7892

ELSA-2025-7892: grafana security update (IMPORTANT)

около 1 года назад
fstec логотип
BDU:2025-06809

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
98%
Критический
около 1 года назад
redos логотип
ROS-20250619-15

Множественные уязвимости grafana

CVSS3: 8.3
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20654-1

Security update for grafana

3 месяца назад

Уязвимостей на страницу