A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40793 | A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser. |
Fixes
Solution
ArcGIS Server Map Service Security 2022 Update 1 Patch https://support.esri.com/en/download/8042
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:56:29.402Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38200
Updated: 2024-08-03T10:45:52.917Z
Status : Modified
Published: 2022-10-25T17:15:55.527
Modified: 2024-11-21T07:16:02.850
Link: CVE-2022-38200
No data.
OpenCVE Enrichment
No data.
EUVD