CVE-2017-12572

Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
splunksplunk
6.3.0
splunksplunk
6.3.1
splunksplunk
6.3.2
splunksplunk
6.3.3
splunksplunk
6.3.4
splunksplunk
6.3.5
splunksplunk
6.3.6
splunksplunk
6.3.7
splunksplunk
6.3.8
splunksplunk
6.4.0
splunksplunk
6.4.1
splunksplunk
6.4.2
splunksplunk
6.4.3
splunksplunk
6.4.4
splunksplunk
6.4.5
splunksplunk
6.5.0
splunksplunk
6.5.0
splunksplunk
6.5.1
splunksplunk
6.5.1
𝑥
= Vulnerable software versions