Back

MEDIUM

Persistent Cross-site Scripting (XSS) in Dashboard Elements

Published Jul 1, 2024

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View that could result in execution of unauthorized JavaScript code in the browser of a user. The “url” parameter of the Dashboard element does not have proper input validation to reject invalid URLs, which could lead to a Persistent Cross-site Scripting (XSS) exploit.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Splunk
Published Jul 1, 2024
Updated Feb 28, 2025
Reserved May 30, 2024
CISA Vulnrichment
Updated Jul 1, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Splunk
Published Jul 1, 2024
Updated Feb 28, 2025
Exploited since n/a
EUVD-2024-36379