PT-2024-21093 · Esri · Portal For Arcgis

Published

2024-04-04

·

Updated

2025-01-08

·

CVE-2024-25695

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Portal for ArcGIS versions prior to 11.2
Description The issue is related to a Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. No privileges are required to execute this attack.
Recommendations For versions prior to 11.2, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to error messages that may contain unsanitized user input until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25695

Affected Products

Portal For Arcgis