1.
CVE-2019-19499 in Grafana 6.4.3: a rogue MySQL data source answers LOCAL INFILE requests to exfiltrate arbitrary files from the Grafana host, turning the 'add a data source' feature into an authenticated arbitrary file read.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2019-19499.