CVE-2016-4856

MEDIUM

Splunk - XSS

Title source: rule

Description

Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

Scores

CVSS v3 4.8
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (12)
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
splunk/splunk
... and 2 more
Published May 12, 2017
Tracked Since Feb 18, 2026