CVE-2023-32715

MEDIUM

Splunk App for Lookup File Editing < 4.0.1 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes that code to run on the user’s machine. The app itself does not contain the potentially malicious JavaScript code. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser, and requires additional user interaction to trigger. The attacker cannot exploit the vulnerability at will.

References (1)

Core 1

Scores

CVSS v3 4.7
EPSS 0.0049
EPSS Percentile 65.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
splunk/splunk_app_for_lookup_file_editing < 4.0.1
Published Jun 01, 2023
Tracked Since Feb 18, 2026