Impact
A malicious user with the "power" role in Splunk Enterprise can create a tour that contains crafted JavaScript. When another user opens the tour link, the script runs inside that user's browser and can access any data the user can normally see, effectively enabling the attacker to steal information or manipulate the client side. The flaw arises because tour content and navigation links are rendered without adequate output encoding, enabling markup injection.
Affected Systems
Splunk Enterprise installations running any of the following firmware releases: 9.4, 10.0, 10.2, and 10.4. The vulnerability affects all versions older than 9.4.14, 10.0.9, 10.2.6, or 10.4.2 respectively. The impact is limited to systems that have Splunk Web enabled and allow users to create tours.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attack requires a user holding the "power" role to craft a tour and another user to click the crafted link, thus the exploitation vector is a user‑initiated action. If both conditions are met, the attacker can execute arbitrary JavaScript and access the victim’s data. The risk is elevated in environments with low entitlement segregation or where Splunk Web is widely used.
OpenCVE Enrichment