Unrated severityNVD Advisory· Published Oct 10, 2014· Updated May 6, 2026
CVE-2014-3147
CVE-2014-3147
Description
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.splunk.com/view/SP-CAAAMSHnvdVendor Advisory
- securitytracker.com/idnvd
News mentions
0No linked articles in our index yet.