CVE-2023-22933: Persistent Cross-Site Scripting through the ‘module’ Tag in a View in Splunk Enterprise

8.0 CVSS

Description

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’.

Classification

CVE ID: CVE-2023-22933

CVSS Base Severity: HIGH

CVSS Base Score: 8.0

Affected Products

Vendor: Splunk

Product: Splunk Enterprise

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.09% (probability of being exploited)

EPSS Percentile: 38.97% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://advisory.splunk.com/advisories/SVD-2023-0203
https://research.splunk.com/application/9ac2bfea-a234-4a18-9d37-6d747e85c2e4

Timeline