Where
-Infinity
0
Severity
4.2
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.

Prerequisites for exploitation:

- Multiple organizations must exist in the Grafana instance

- Victim must be on a different organization than the one specified in the URL

First published (updated )
Severity
7.6
XSS, Path Traversal
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0.

The open redirect can be chained with path traversal vulnerabilities to achieve XSS.

Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

First published (updated )
Severity
7.6
EPSS
0.05%
XSS, Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Remedy

Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203