Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
grafana-exploit-CVE-2021-43798 — Shell-based exploit for Grafana CVE-2021-43798, enabling unauthorized arbitrary file read via directory traversal on versions 8.0.0-beta1 through 8.3.0. | Kitploit
Tools/GitHubGitHub/victorhorowitz/grafana-exploit-cve-2021-43798
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubvictorhorowitz/grafana-exploit-cve-2021-43798

grafana-exploit-CVE-2021-43798

Shell-based exploit for Grafana CVE-2021-43798, enabling unauthorized arbitrary file read via directory traversal on versions 8.0.0-beta1 through 8.3.0.

View Repository
3 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

grafana-exploit-CVE-2021-43798

About

What is this exploit used for ?

  • used for the Grafana Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798)
  • allows access to local files using directory traversal

What grafana versions will this exploit work for?

  • will work for Grafana versions 8.0.0-beta1 through 8.3.0.
    • Versions 8.07, 8.1.8, 8.2.7 and 8.3.1 are patched.

Operating System Compatibility

  • this exploit was written to work on Linux targets

Disclaimer

  • only use this exploit with explicit permission from the network owner
  • code cannot be used to violate the law
  • the author of this project is not responsible for the misuse of this code

Usage

Syntax

  • ./grafana.sh <ip> <plugin file> <file path> <port # optional>

Example

  • ./grafana.sh 10.10.10.10 plugins.txt /etc/passwd

Description

  • The plugins.txt file is in the repository and can be used for the plugin file parameter
  • There are three required parameters:
    • ip
    • plugin file
    • file path
  • If the grafana instance is not running on the default 3000 port, then add the port number as the 4th parameter
Download Tool