HomeGrafanaCVE-2025-4123

CVE-2025-4123

HIGH
7.6CVSS
Published: 2025-05-22
Updated: 2025-08-15
AI Analysis

Description

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
low
Availability
low
Weaknesses
CWE-79CWE-601

Metadata

Primary Vendor
GRAFANA
Published
5/22/2025
Last Modified
8/15/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

grafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafanagrafana : grafana

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-4123 | HIGH Severity | CVEDatabase.com | CVEDatabase.com