PT-2024-21099 · Esri · Arcgis Enterprise Builder

Published

2024-04-04

·

Updated

2025-04-11

·

CVE-2024-25700

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below
Description: The issue is a stored Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a crafted link stored in a web map link. When clicked, this link could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Recommendations: For Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below, update to a version above 11.1 to resolve the issue. As a temporary workaround, consider restricting access to web map links to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25700

Affected Products

Arcgis Enterprise Builder