Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x48-4r9f-3jvf

Опубликовано: 05 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

EPSS

Процентиль: 73%
0.00786
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
nvd
больше 3 лет назад

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

EPSS

Процентиль: 73%
0.00786
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79