PT-2024-21094 · Esri · Portal For Arcgis

Published

2024-04-04

·

Updated

2025-01-08

·

CVE-2024-25696

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Portal for ArcGIS versions <=11.0
Description The issue is related to a Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a crafted link. When the victim accesses the page editor, an image will render in the victim's browser. The privileges required to execute this attack are high.
Recommendations For Portal for ArcGIS versions <=11.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25696

Affected Products

Portal For Arcgis