Description
There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40803 | There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser. |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only) | HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only) |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:53:29.678Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38210
Updated: 2024-08-03T10:45:53.092Z
Status : Modified
Published: 2022-12-29T20:15:09.997
Modified: 2024-11-21T07:16:04.173
Link: CVE-2022-38210
No data.
OpenCVE Enrichment
No data.
EUVD