How I Discovered a CRITICAL Vulnerability in Grafana | Chaining XSS & SSRF | CVE-2025-4123
Автор: Alvaro Balada
Загружено: 2025-09-06
Просмотров: 1588
In this video, I break down CVE-2025-4123, a complex unauthenticated open redirect in Grafana. Watch as I escalate it to Full Read SSRF using a headless browser, and uncover a second exploitation path leading to XSS → one-click account takeover.
The video includes clear technical animations showing the full methodology from discovery to exploitation.
💡 Disclaimer: This content is for educational purposes only. Do not attempt to exploit vulnerabilities on systems you do not own or have explicit permission to test. Always follow responsible disclosure best practices.
Chapters:
00:00 - Introduction
01:00 - What's Grafana?
03:31 - Static Handler function
05:54 - Objective: Open Redirect
07:45 - Crafting the Payload
11:47 - Full Read SSRF
15:00 - XSS to Account Takeover
18:37 - Impact in the real world
Resources:
CVE-2025-4123 Exploit: https://github.com/NightBloodz/CVE-20...
Original Blogpost: https://nightbloodz.github.io/grafana...
Official Grafana Blogpost: https://grafana.com/blog/2025/05/21/g...
Official Fix: https://github.com/grafana/grafana/co...
About Me:
Website: https://nightbloodz.github.io/
LinkedIn: / alvarobalada
Medium: / nightbloodz
X/Twitter: https://x.com/nightbloodz_
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: