PT-2022-24284 · Esri · Esri Portal For Arcgis

Published

2022-12-29

·

Updated

2023-01-05

·

CVE-2022-38207

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 10.7.1 through 10.8.1
Description The issue is related to a reflected XSS vulnerability that may allow a remote, unauthenticated attacker to create a crafted link. When clicked, this link could execute arbitrary JavaScript code in the victim's browser.
Recommendations For Esri Portal for ArcGIS versions 10.7.1 and 10.8.1, consider disabling any features that may be used to create crafted links until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-38207

Affected Products

Esri Portal For Arcgis