S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41174 Scanner

CVE-2021-41174 scanner - Cross-Site Scripting (XSS) vulnerability in Grafana

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41174
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(‘alert(1)’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
grafanaby grafana
>= 8.0.0, < 8.2.3
Updated Aug 21, 2026View on NVD →
Detail

Grafana is an open-source monitoring and observability platform used by businesses and individuals worldwide. Its primary purpose is to help users maintain oversight of their digital assets, including servers, networks, and applications. With its user-friendly interface and easy-to-customize dashboard, Grafana has become a popular choice for managing complex IT infrastructures.

The CVE-2021-41174 vulnerability is a critical security flaw that was recently discovered in Grafana. This vulnerability can be exploited by attackers who are able to trick a victim into visiting a URL that references a vulnerable page. Once the victim visits the URL, arbitrary JavaScript content can be executed in the context of the victim's browser. This can have serious consequences for users who are unaware of the vulnerability.

If CVE-2021-41174 is successfully exploited, it can lead to a variety of attacks, including stealing credentials, accessing sensitive data, and injecting malicious code into the victim's system. With the ability to execute arbitrary code within a victim's browser, this vulnerability has the potential to cause significant damage to businesses and individuals alike.

At s4e.io, we offer a range of pro features that can help users quickly and easily identify and mitigate vulnerabilities in their digital assets. With our advanced scanning tools, comprehensive threat intelligence database, and real-time alerts, we help businesses and individuals stay one step ahead of attackers. So if you're concerned about the security of your digital assets, sign up for s4e.io today and start protecting yourself and your business from the latest threats.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These precautions include: 

  • Upgrading to the latest version of Grafana 
  • Using a reverse proxy or similar tool to block access to the literal string {{ in the URL 
  • Being cautious when clicking on links from untrusted sources 
  • Educating employees and other users about the risks of visiting unknown or suspicious URLs 
  • Using endpoint protection software to detect and block malicious code 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.