PT-2022-24266 · Esri · Esri Portal For Arcgis

Gustavo Silva

·

Published

2022-08-16

·

Updated

2023-10-03

·

CVE-2022-38189

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS (affected versions not specified)
Description A stored Cross Site Scripting (XSS) issue may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-38189

Affected Products

Esri Portal For Arcgis