PT-2021-18097 · Esri · Esri Portal For Arcgis
Published
2021-10-01
·
Updated
2022-03-30
·
CVE-2021-29109
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Esri Portal for ArcGIS versions prior to 10.9
Description:
A reflected XSS issue may allow a remote attacker to convince a user to click on a crafted link, potentially executing arbitrary JavaScript code in the user's browser.
Recommendations:
For Esri Portal for ArcGIS versions prior to 10.9, update to a version above 10.9 to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable links to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esri Portal For Arcgis