# grafana-exploit-CVE-2021-43798
# About
### What is this exploit used for ?
- used for the Grafana Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798)
- allows access to local files using directory traversal
### What grafana versions will this exploit work for?
- will work for Grafana versions 8.0.0-beta1 through 8.3.0.
- Versions 8.07, 8.1.8, 8.2.7 and 8.3.1 are patched.
### Operating System Compatibility
- this exploit was written to work on Linux targets
### Disclaimer
- only use this exploit with explicit permission from the network owner
- code **cannot** be used to violate the law
- the author of this project is not responsible for the misuse of this code
# Usage
### Syntax
- `./grafana.sh <ip> <plugin file> <file path> <port # optional>`
### Example
- `./grafana.sh 10.10.10.10 plugins.txt /etc/passwd`
### Description
- The plugins.txt file is in the repository and can be used for the `plugin file` parameter
- There are three required parameters:
- `ip`
- `plugin file`
- `file path`
- If the grafana instance is not running on the default 3000 port, then add the port number as the 4th parameter
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view