Impact
The vulnerability is a stored cross‑site scripting flaw in Splunk Enterprise dashboard rendering. A non‑admin or power user can save a malicious dashboard that injects JavaScript into the tooltip of a sparkline cell. When another user opens the dashboard and hovers over the cell, the script executes in the victim’s browser with the victim’s privileges, allowing the attacker to read page data and access any resources available to that user.
Affected Systems
Affected vendors include Splunk Enterprise. All versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. These versions run the dashboard view and tooltip renderer that fails to escape content.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in KEV. The attack requires a non‑admin or power user to construct a malicious dashboard and a target user to view it. Once the target hovers over a sparkline cell, the payload runs in the target’s browser, giving the attacker access to data and system capabilities available to the target.
OpenCVE Enrichment