PT-2022-24278 · Esri · Esri Portal For Arcgis Quick Capture Web Designer

Hussein Bahmad

·

Published

2022-11-15

·

Updated

2022-11-21

·

CVE-2022-38201

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 through 10.9.1
Description An unvalidated redirect issue exists, allowing a remote, unauthenticated attacker to potentially trick an authenticated user into accessing a domain controlled by the attacker.
Recommendations For Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 through 10.9.1, update to a version that includes the fix for this issue to prevent exploitation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-38201

Affected Products

Esri Portal For Arcgis Quick Capture Web Designer