CVE-2022-26148: Grafana & Zabbix Integration – Credentials Disclosure

CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2022-26148: Grafana & Zabbix Integration – Credentials Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-26148: Grafana & Zabbix Integration – Credentials Disclosure

漏洞描述

Grafana through 7.3.4, when integrated with Zabbix, contains a credential disclosure vulnerability. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享