CVE-2019-5727
Summary
| CVE | CVE-2019-5727 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-21 01:29:00 UTC |
| Updated | 2019-02-22 13:49:00 UTC |
| Description | Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Splunk Enterprise and Splunk Light address one vulnerability | Splunk | MISC | www.splunk.com | Vendor Advisory |
| Splunk Enterprise and Splunk Lite CVE-2019-5727 HTML Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730137 Splunk Enterprise and Light Persistent Cross Site Scripting Vulnerability (SP-CAAAQAF)