PT-2024-21093 · Esri · Portal For Arcgis
Published
2024-04-04
·
Updated
2025-01-08
·
CVE-2024-25695
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Portal for ArcGIS versions prior to 11.2
Description
The issue is related to a Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. No privileges are required to execute this attack.
Recommendations
For versions prior to 11.2, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to error messages that may contain unsanitized user input until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Portal For Arcgis