5.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Description
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the `/app/search/table` endpoint, which could result in execution of unauthorized JavaScript code in the browser of a user.
Basic Information
ID
CVE-2025-20367
Source
cisco
Published
Oct 1, 2025 at 16:08
Affected Product
Vendor
Splunk
Product
Splunk Enterprise
Version
10.0
Affected Versions
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Cloud Platform 9.3.2408
Splunk Splunk Cloud Platform 9.2.2406
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Cloud Platform 9.3.2408
Splunk Splunk Cloud Platform 9.2.2406