Grafana Flaws Allow User Redirection and Code Execution in Dashboards

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

Grafana Flaws Allow User Redirection and Code Execution in Dashboards

Post by Shane1145 »

Grafana Labs has released critical security patches addressing two significant vulnerabilities that could enable attackers to redirect users to malicious websites and execute arbitrary code within dashboard environments.

The security update addresses CVE-2025-6023, a high-severity cross-site scripting (XSS) vulnerability, and CVE-2025-6197, a medium-severity open redirect flaw, both discovered through the company’s bug bounty program.

https://gbhackers.com/grafana-flaws/
Post Reply