Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.
References
Link | Resource |
---|---|
https://www.splunk.com/view/SP-CAAAPYC | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-08-05 14:29
Updated : 2017-08-15 11:43
NVD link : CVE-2017-12572
Mitre link : CVE-2017-12572
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
splunk
- splunk