PT-2024-21104 · Esri · Esri Portal For Arcgis Enterprise Web App Builder

Published

2024-04-04

·

Updated

2025-01-31

·

CVE-2024-25708

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 through 10.9.1
Description The issue is a stored Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Recommendations For Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 through 10.9.1, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25708

Affected Products

Esri Portal For Arcgis Enterprise Web App Builder