Impact
The vulnerability is characterized as improper neutralization of input during web page generation, which is a form of cross‑site scripting. Splunk Enterprise allows untrusted input to be incorporated into web pages without adequate sanitization, enabling an attacker to inject arbitrary JavaScript. When executed in a victim’s browser, the script can steal session tokens, capture keystrokes, or modify page content, potentially compromising the confidentiality and integrity of the system.
Affected Systems
Affected systems are Splunk Enterprise customers using any of the following released versions: 10.4.3, 10.2.7, 10.0.10, or 9.4.15. All of these releases contain the underlying code paths that perform unsafe rendering of user‑supplied data. Users must upgrade to the specified corrected releases or newer to eliminate the flaw.
Risk and Exploitability
Risk and exploitability are elevated because the vulnerability is a classic web‑application weakness governed by CWE‑707. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but common XSS exploitation techniques (e.g., malformed input in query parameters or custom dashboard widgets) suggest that the flaw is readily exploitable when users interact with the affected components. The attack vector is likely through the web interface, and depending on user privileges, an authenticated or unauthenticated attacker may be able to craft a payload that executes in the context of any logged‑in user who views the vulnerable page.
OpenCVE Enrichment