xsspresso
xsspresso
Tags/ Grafana

Grafana

2 writeups tagged with Grafana

WebEasyLinux

HTB — Planning

Grafana SSRF pivots to an internal Grafana instance. Credential reuse for SSH, then environment variable injection via root cron.

#Grafana#SSRF#Cron
May 31, 2025HackTheBox
WebMediumLinux

HTB — BigBang

WordPress BuddyForms plugin SSRF for local file read. Grafana SQLite injection for credentials. Telescope log viewer arbitrary file read for root key.

#WordPress#SSRF#Grafana
Jan 26, 2025HackTheBox