Description
There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
No analysis available yet.
Remediation
Vendor Solution
a. Disable the ArcGIS Services directory b. Install ArcGIS for Server Security 2022 Update 1 Patch
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40791 | There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser. |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:56:12.281Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38198
Updated: 2024-08-03T10:45:53.004Z
Status : Modified
Published: 2022-10-25T17:15:55.420
Modified: 2024-11-21T07:16:02.573
Link: CVE-2022-38198
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD