Grafana Pentest

Pentest Grafana instances for misconfigurations and CVE-2024-9264 SQL Expressions RCE/LFI vulnerability. Use this skill whenever you need to assess Grafana security, check for exposed credentials in config files, enumerate data sources, or test for the CVE-2024-9264 vulnerability that allows authenticated users to execute arbitrary commands via DuckDB shellfs extension. Trigger this skill for any Grafana security assessment, penetration test, or vulnerability scan.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/network-services-pentesting/pentesting-web/grafana commit 9af11d3335

Frequently asked questions

npx skillmds@latest add abelrguezr/grafana-pentest