TGViewer
Netlas.io Netlas.io @netlas · 2.34K subscribers
Post #75 416
CVE-2023-3128: Authentication Bypass in Grafana, 9.4 rating ❗️
CVE vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

During Grafana's Azure AD account validation, an attacker can spoof the profile email field and hijack the account.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/iqMVz
👉🏻 Dork: http.favicon.hash_sha256:80a7f87a79169cf0ac1ed3250d7c509368190a97bc7182cd4705deb8f8c70174 AND http.title:"Grafana"
  • 👾 4
  • 🔥 2
More from @netlas
  1. Oct 7, 2026CVE-2026-106445 & CVE-2026-106446: Two RCE flaws in Handlebars.js, up to 9.8 rating ‍🔥 Tw…
  2. Oct 6, 2026🎯 Netlas v1.10 Track changes in your attack surface with the new private scan comparison.…
  3. Oct 6, 2026CVE-2026-88779: DoS vulnerability in Citrix NetScaler ADC & Gateway, 8.7 rating ‍🔥 A rece…
  4. Oct 5, 2026CVE-2026-96940: EoP vulnerability in MS Exchange Server, 8.8 rating ‍🔥 Microsoft has upda…
  5. Oct 2, 2026CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 ratin…
  6. Sep 29, 2026CVE-2026-88771 & CVE-2026-88772: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gate…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →