CVE-2022-43569 Information
Nov 05, 2022
cve
Description
In Splunk Enterprise versions below 8.1.12 8.2.9 and 9.0.2 an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
Reference
https://www.splunk.com/en_us/product-security/announcements/svd-2022-1109.html https://research.splunk.com/application/062bff76-5f9c-496e-a386-cb1adcf69871/
Share on: