Description
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
No analysis available yet.
Remediation
Vendor Workaround
This issue may be mitigated by securing the feature service.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15757 | A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser. |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:58:53.616Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29116
Updated: 2024-08-03T22:02:51.085Z
Status : Modified
Published: 2021-12-07T11:15:08.020
Modified: 2024-11-21T06:00:44.950
Link: CVE-2021-29116
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD