6.1
CVSSv3

CVE-2023-40592

Published: 30/08/2023 Updated: 10/04/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of arbitrary commands on the Splunk platform instance.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splunk splunk cloud platform

splunk splunk 9.1.0

splunk splunk