Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43798-EXPLOIT — A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal | Kitploit
Tools/GitHubGitHub/k3ystr0k3r/cve-2021-43798-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubk3ystr0k3r/cve-2021-43798-exploit

CVE-2021-43798-EXPLOIT

A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal

View Repository
4122 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-43798 - Grafana Directory Traversal 🔍

Grafana is an open-source platform for monitoring and observability. Versions 8.0.0-beta1 through 8.3.0 (except for patched versions) are vulnerable to a directory traversal attack, allowing unauthorized access to local files. This vulnerability does not affect Grafana Cloud. The vulnerability exists in the handling of the URL path <grafana_host_url>/public/plugins//. By manipulating the <plugin_id> parameter, an attacker can traverse directories and access files outside the intended directory.

Impact 💥

An attacker could exploit this vulnerability to access sensitive files on the host system, potentially leading to further compromise of the Grafana instance or the host system itself.

Affected Versions ❗️

Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) are affected by this vulnerability.

Disclaimer 🚨

This exploit is intended for educational purposes only. Misuse of this exploit or any information related to it is not condoned and is the sole responsibility of the user.

Download Tool