Description
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23006 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri portal For Arcgis Linux Linux linux Kernel Microsoft Microsoft windows |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Esri
Esri portal For Arcgis Linux Linux linux Kernel Microsoft Microsoft windows |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:03:39.985Z
Reserved: 2024-02-09T19:07:07.974Z
Link: CVE-2024-25690
Updated: 2024-08-01T23:52:04.900Z
Status : Analyzed
Published: 2024-04-04T18:15:09.580
Modified: 2025-01-08T15:20:46.477
Link: CVE-2024-25690
No data.
OpenCVE Enrichment
No data.
EUVD