vulnerability
Splunk: CVE-2023-46213: Cross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search Page
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:M/C:P/I:P/A:N) | Nov 16, 2023 | Apr 7, 2025 | Oct 31, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:M/C:P/I:P/A:N)
Published
Nov 16, 2023
Added
Apr 7, 2025
Modified
Oct 31, 2025
Description
In Splunk Enterprise versions below 9.0.7 and 9.1.2, the “Show syntax highlighted” feature of the Search page does not effectively escape log file characters.This vulnerability lets an attacker craft a log file which can execute unauthorized Javascript code in the browser of a user that interacts with events in the malicious log file in a specific way.
Solution
splunk-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.