<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:29:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-36997 — Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-36997</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Splunk Enterprise, Splunk Cloud Platform, splunk, splunk_cloud_platform&lt;/p&gt;
&lt;p&gt;In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Splunk Enterprise, Splunk Cloud Platform, splunk, splunk_cloud_platform&lt;/p&gt;
&lt;p&gt;In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-36997</guid>
    </item>
  </channel>
</rss>
