Title: Cross-site Scripting vulnerability in Portal for ArcGIS
CVE ID: CVE-2024-25697
CVSSv3.1 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Vendor: Environmental Systems Research Institute, Inc. (Esri)
Products: Portal for ArcGIS
Advisory Release Date: 11-04-2024
Advisory URL: https://labs.integrity.pt/advisories/cve-2024-25697
Credits: Discovery by Pedro Valadares Pinho <pedro.pinho[at]devoteam.com>
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy