Логотип exploitDog
bind: "CVE-2025-4123"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-4123"

Количество 12

Количество 12

ubuntu логотип

CVE-2025-4123

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
redhat логотип

CVE-2025-4123

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
nvd логотип

CVE-2025-4123

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
debian логотип

CVE-2025-4123

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
EPSS: Средний
rocky логотип

RLSA-2025:7894

3 месяца назад

Important: grafana security update

EPSS: Средний
rocky логотип

RLSA-2025:7892

около 1 месяца назад

Important: grafana security update

EPSS: Средний
github логотип

GHSA-q53q-gxq9-mgrj

6 месяцев назад

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
EPSS: Средний
oracle-oval логотип

ELSA-2025-7894

6 месяцев назад

ELSA-2025-7894: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7893

6 месяцев назад

ELSA-2025-7893: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7892

4 месяца назад

ELSA-2025-7892: grafana security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-06809

6 месяцев назад

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
EPSS: Средний
redos логотип

ROS-20250619-15

5 месяцев назад

Множественные уязвимости grafana

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
15%
Средний
6 месяцев назад
redhat логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
15%
Средний
6 месяцев назад
nvd логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
15%
Средний
6 месяцев назад
debian логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
15%
Средний
6 месяцев назад
rocky логотип
RLSA-2025:7894

Important: grafana security update

15%
Средний
3 месяца назад
rocky логотип
RLSA-2025:7892

Important: grafana security update

15%
Средний
около 1 месяца назад
github логотип
GHSA-q53q-gxq9-mgrj

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
15%
Средний
6 месяцев назад
oracle-oval логотип
ELSA-2025-7894

ELSA-2025-7894: grafana security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-7893

ELSA-2025-7893: grafana security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-7892

ELSA-2025-7892: grafana security update (IMPORTANT)

4 месяца назад
fstec логотип
BDU:2025-06809

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
15%
Средний
6 месяцев назад
redos логотип
ROS-20250619-15

Множественные уязвимости grafana

CVSS3: 8.3
5 месяцев назад

Уязвимостей на страницу