PT-2024-7824 · Esri · Esri Portal For Arcgis
Published
2024-06-11
·
Updated
2024-10-15
·
CVE-2024-38039
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Esri Portal for ArcGIS versions 11.0 and below
Description
The issue is related to an HTML injection vulnerability that may allow a remote, authenticated attacker to create a crafted link which, when clicked, could render arbitrary HTML in the victim's browser. This does not result in any stateful change or the rendering of customer data. The vulnerability is associated with the incorrect neutralization of special elements in output used by an incoming component, which could allow an attacker to execute arbitrary HTML code.
Recommendations
For Esri Portal for ArcGIS versions 11.0 and below, update to a version above 11.0 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esri Portal For Arcgis