Description
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Font-official webfonts plugin of Fonts For Web Directory Traversal (7.5)
MySQL CVE-2014-0430 Vulnerability (CVE-2014-0430)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-7724)
Elgg Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3964)
WordPress Plugin iPages Flipbook For WordPress Cross-Site Scripting (1.4.2)