Impact
Splunk Enterprise allows a user with the "power" role to embed arbitrary JavaScript in the sparkline format settings of a dashboard. When a different user later views the dashboard, the malicious script is rendered in their browser and can execute with that user's privileges. If the viewer holds an "admin" role, the script has full access to data available to Splunk Web and can perform actions on the victim's account. This vulnerability is described by CWE-79 and is limited to the unescaped tooltip rendering of the sparkline options.
Affected Systems
The affected software is Splunk Enterprise for all releases earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The issue only exists in configurations where Splunk Web is enabled. Users with the "power" role can create the malicious payload, and other users with the "admin" role can be exploited.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV, suggesting a low to moderate likelihood of widespread exploitation. Nonetheless, achieving exploitation requires the attacker to phish a user with the "power" role to deliver a request that stores the malicious script, and the victim must subsequently view the affected dashboard. Because the script runs in the victim's browser context, it can harvest credentials and data that the victim’s role permits. The overall exposure is therefore confined to environments where the attacker can compromise a power‑role user and trick an admin‑role user into browsing the compromised dashboard.
OpenCVE Enrichment