VDB

CVE-2025-4123

CVE-2025-4123 PUBLISHED KEV CVSS 6.099999904632568 MEDIUM

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

EPSS 97.01% · 99.9th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
97.01%
99.9th percentile

Affected Products

VendorProductVersions
Bitnamigrafana11.0.0, 12.0.0, 0
Bitnamigrafana0, 12.0.0, 11.0.0

Timeline

  • CVE Published
  • May 31, 2022 VulnCheck KEV Exploitation
  • Oct 23, 2024 VulnCheck XDB Entry
  • May 22, 2025 EPSS Score
  • May 23, 2025 VulnCheck XDB Entry
  • May 27, 2025 EPSS Score
  • Jun 3, 2025 VulnCheck XDB Entry
  • Jun 4, 2025 EPSS Score
  • Jun 4, 2025 VulnCheck XDB Entry
  • Jun 7, 2025 VulnCheck XDB Entry
  • Jun 18, 2025 VulnCheck XDB Entry
  • Jun 19, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›