Impact
In Splunk Enterprise versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user with the "power" role can store a Dashboard Studio workflow action containing a crafted URL; when any authenticated user later selects that stored action and clicks Continue, the embedded JavaScript runs in the victim’s browser, exposing data or actions available through Splunk Web, thereby presenting a stored cross‑site scripting flaw that can lead to disclosure of sensitive information and execution of arbitrary client‑side code.
Affected Systems
The vulnerable product is Splunk Enterprise from the vendor Splunk; affected versions are those below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and the flaw requires the presence of Splunk Web and a user holding the "power" role to create the malicious action.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity for confidentiality, integrity, and availability of the browser context; the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires phishing or social engineering to get an authenticated user to trigger the vulnerable action, and does not provide remote code execution on the server but enables potent client‑side capabilities that could be leveraged for further credential theft or session hijacking.
OpenCVE Enrichment