PT-2024-7824 · Esri · Esri Portal For Arcgis

Published

2024-06-11

·

Updated

2024-10-15

·

CVE-2024-38039

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 11.0 and below
Description The issue is related to an HTML injection vulnerability that may allow a remote, authenticated attacker to create a crafted link which, when clicked, could render arbitrary HTML in the victim's browser. This does not result in any stateful change or the rendering of customer data. The vulnerability is associated with the incorrect neutralization of special elements in output used by an incoming component, which could allow an attacker to execute arbitrary HTML code.
Recommendations For Esri Portal for ArcGIS versions 11.0 and below, update to a version above 11.0 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2024-09324
CVE-2024-38039

Affected Products

Esri Portal For Arcgis