CVE-2024-9264: Execute Arbitrary Code in Grafana, 9.9 rating π₯π₯π₯
Grafana users at Viewer level and above can perform command injection using a vulnerability in SQL Expressions.
More then 104k instances at Netlas.io:
π Link: https://nt.ls/oQJHO
π Dork: http.favicon.hash_sha256:80a7f87a79169cf0ac1ed3250d7c509368190a97bc7182cd4705deb8f8c70174 AND http.title:"Grafana"
Vendor's advisory: https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/
Post #246
781

- π₯ 5
- πΎ 2
- π 1