There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).

Project Subscriptions

Vendors Products
Portal For Arcgis Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-29721 There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
Fixes

Solution

https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8... https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8095


Workaround

No workaround given by the vendor.

History

Thu, 10 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
Title BUG-000155004 HTML injection issue in Portal for ArcGIS.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T18:40:10.575Z

Reserved: 2023-02-15T00:00:00

Link: CVE-2023-25833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-05-10T02:15:08.933

Modified: 2024-11-21T07:50:17.503

Link: CVE-2023-25833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses