Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.
2017-08-05T21:29:00.177
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | splunk | splunk | 6.3.0 | Yes |
Application | splunk | splunk | 6.3.1 | Yes |
Application | splunk | splunk | 6.3.2 | Yes |
Application | splunk | splunk | 6.3.3 | Yes |
Application | splunk | splunk | 6.3.4 | Yes |
Application | splunk | splunk | 6.3.5 | Yes |
Application | splunk | splunk | 6.3.6 | Yes |
Application | splunk | splunk | 6.3.7 | Yes |
Application | splunk | splunk | 6.3.8 | Yes |
Application | splunk | splunk | 6.4.0 | Yes |
Application | splunk | splunk | 6.4.1 | Yes |
Application | splunk | splunk | 6.4.2 | Yes |
Application | splunk | splunk | 6.4.3 | Yes |
Application | splunk | splunk | 6.4.4 | Yes |
Application | splunk | splunk | 6.4.5 | Yes |
Application | splunk | splunk | 6.5.0 | Yes |
Application | splunk | splunk | 6.5.0 | Yes |
Application | splunk | splunk | 6.5.1 | Yes |
Application | splunk | splunk | 6.5.1 | Yes |