Description
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23013 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low. |
References
History
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low. | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low. |
Wed, 08 Jan 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri portal For Arcgis |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Esri
Esri portal For Arcgis |
Tue, 08 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low. | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low. |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:02:47.833Z
Reserved: 2024-02-09T19:07:07.976Z
Link: CVE-2024-25697
Updated: 2024-08-01T23:52:04.905Z
Status : Modified
Published: 2024-04-04T18:15:11.027
Modified: 2025-04-10T19:15:57.740
Link: CVE-2024-25697
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD