There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-40802 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS vulnerability in Portal for ArcGIS Reflected XSS vulnerability in Portal for ArcGIS

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T14:53:41.363Z

Reserved: 2022-08-12T00:00:00.000Z

Link: CVE-2022-38209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-29T20:15:09.917

Modified: 2024-11-21T07:16:04.047

Link: CVE-2022-38209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.