Grafana是Grafana开源的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana存在安全漏洞,该漏洞源于客户端路径遍历和开放重定向结合,可能导致跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana | 10.4.18+security-01< 10.4.19 |
affected |
11.2.9+security-01< 11.2.10 |
affected | ||
11.3.6+security-01< 11.3.7 |
affected | ||
11.4.4+security-01< 11.4.5 |
affected | ||
11.5.4+security-01< 11.5.5 |
affected | ||
11.6.1+security-01< 11.6.2 |
affected | ||
12.0.0+security-01< 12.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An open redirect vulnerability in Grafana can be chained with other issues, such as XSS or SSRF, to increase impact. An attacker may exploit the redirect to target internal services or deliver malicious JavaScript, potentially leading to internal data exposure or account takeover. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4123.yaml | POC Details |
| 2 | Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF | https://github.com/NightBloodz/CVE-2025-4123 | POC Details |
| 3 | CVE-2025-4123 | https://github.com/kk12-30/CVE-2025-4123 | POC Details |
| 4 | None | https://github.com/imbas007/CVE-2025-4123-template | POC Details |
| 5 | CVE-2025-4123 - Grafana Tool | https://github.com/ynsmroztas/CVE-2025-4123-Exploit-Tool-Grafana- | POC Details |
| 6 | CVE-2025-4123 | https://github.com/B1ack4sh/Blackash-CVE-2025-4123 | POC Details |
| 7 | Escaner para encontrar vulnerabilidad CVE-2025-4123 grafana | https://github.com/DesDoTvl/CVE-2025-4123grafana | POC Details |
| 8 | None | https://github.com/punitdarji/Grafana-cve-2025-4123 | POC Details |
| 9 | Grafana CVE-2025-4123-POC | https://github.com/ItsNee/Grafana-CVE-2025-4123-POC | POC Details |
| 10 | CVE-2025-4123 Grafana Open Redirect Exploit | https://github.com/MorphyKutay/CVE-2025-4123-Exploit | POC Details |
| 11 | CVE-2025-4123 | https://github.com/Ashwesker/Blackash-CVE-2025-4123 | POC Details |
| 12 | Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF | https://github.com/NightBlood0/CVE-2025-4123 | POC Details |
| 13 | Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF | https://github.com/NightBloodZ/CVE-2025-4123 | POC Details |
| 14 | CVE-2025-4123 | https://github.com/Ashwesker/Ashwesker-CVE-2025-4123 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet