PT-2025-9554 · Esri · Arcgis Server
Published
2025-02-18
·
Updated
2025-03-04
·
CVE-2024-51953
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ArcGIS Server versions 10.9.1 through 11.3
Description
The issue is a stored Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a stored crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity, while having no impact to availability.
Recommendations
For ArcGIS Server versions 10.9.1 through 11.3, consider restricting publisher capabilities to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using links from untrusted sources and restrict access to sensitive areas of the application to reduce the potential for arbitrary JavaScript code execution.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcgis Server