Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8267-g4r9-6r3v

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

EPSS

Процентиль: 42%
0.00199
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
больше 3 лет назад

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

EPSS

Процентиль: 42%
0.00199
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79