VDB
CVE-2025-4123
CVE-2025-4123
PUBLISHED
KEV
CVSS 6.099999904632568 MEDIUM
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
EPSS 97.01% · 99.9th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
97.01%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 11.0.0, 12.0.0, 0 |
| Bitnami | grafana | 0, 12.0.0, 11.0.0 |
Timeline
- CVE Published
- May 31, 2022 VulnCheck KEV Exploitation
- Oct 23, 2024 VulnCheck XDB Entry
- May 22, 2025 EPSS Score
- May 23, 2025 VulnCheck XDB Entry
- May 27, 2025 EPSS Score
- Jun 3, 2025 VulnCheck XDB Entry
- Jun 4, 2025 EPSS Score
- Jun 4, 2025 VulnCheck XDB Entry
- Jun 7, 2025 VulnCheck XDB Entry
- Jun 18, 2025 VulnCheck XDB Entry
- Jun 19, 2025 Coalition ESS Score
References
- https://grafana.com/security/security-advisories/cve-2025-4123/ url
- https://nvd.nist.gov/vuln/detail/CVE-2025-4123 url
- https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/ url
- Vulnérabilité dans Grafana advisory
- Multiples vulnérabilités dans Grafana advisory
- Nuclei Template exploit