Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dat Phung

#30261of 56,328
9Total CVSS
Vulnerabilities · 1
PT-2025-30013
9.0
2025-06-11
Grafana · Grafana Oss · CVE-2025-6197
**Name of the Vulnerable Software and Affected Versions** Grafana OSS versions 11.3.0 through 11.3.7 Grafana OSS versions 11.4.0 through 11.4.5 Grafana OSS versions 11.5.0 through 11.5.5 Grafana OSS versions 11.6.0 through 11.6.2 Grafana OSS versions 12.0.0 through 12.0.1 **Description** An open redirect issue exists in the OSS organization switching functionality. This flaw allows a remote attacker to redirect users to an arbitrary external website. For successful exploitation, the Grafana instance must contain multiple organizations, and the victim must belong to an organization different from the one specified in the URL. This open redirect can be chained with path traversal to facilitate cross-site scripting (XSS) attacks, where malicious scripts are injected into trusted websites. **Recommendations** Update to version 11.3.8+security-01 Update to version 11.4.6+security-01 Update to version 11.5.6+security-01 Update to version 11.6.3+security-01 Update to version 12.0.2+security-01