vendor:
Splunk
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Splunk
Affected Version From: 4.2.2002
Affected Version To: 4.2.2002
Patch Exists: NO
Related CWE:
CPE: a:splunk:splunk:4.2.2
Platforms Tested:
2020
Cross-Site Scripting Vulnerability in Splunk
The vulnerability exists in Splunk due to insufficient sanitization of user-supplied data. An attacker can exploit this vulnerability to execute arbitrary HTML and script code in the context of the affected site, potentially leading to the theft of authentication credentials and other attacks.
Mitigation:
Upgrade to a non-vulnerable version of Splunk. Apply patches or updates provided by the vendor.