Impact
The vulnerability arises when Splunk Web accepts messages without validating their origin, enabling an attacker to inject malicious JavaScript that runs in the victim's browser. This can expose all data the victim can see and allow the attacker to perform actions that compromise system integrity. The weakness is a classic reflected XSS flaw under CWE-79.
Affected Systems
The flaw affects Splunk Enterprise customers running any of the following versions: 10.4.1 or earlier, 10.2.5 or earlier, 10.0.8 or earlier, and 9.4.13 or earlier. All installations that have Splunk Web enabled are potentially exposed.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity, and there is no publicly available EPSS data, so current exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog, but it requires initial social‑engineering of a user to get them to load a malicious page. Because the attacker must first convince a legitimate user to visit a crafted link, the vector relies on user interaction, which mitigates spontaneous remote attacks but still poses a significant risk in environments with high user turnover or weak user awareness. If an attacker succeeds in convincing a user to visit a malicious page, the malicious JavaScript will run in that user's session, yielding the same privileges as the victim and potentially impacting all data and system functions visible to that user.
OpenCVE Enrichment