Description
There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23014 | There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. |
References
History
Thu, 30 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Tue, 08 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri portal For Arcgis |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:-:*:*:*:*:*:*:* cpe:2.3:a:esri:portal_for_arcgis:10.8.1:*:*:*:*:*:*:* cpe:2.3:a:esri:portal_for_arcgis:10.9.1:*:*:*:*:*:*:* cpe:2.3:a:esri:portal_for_arcgis:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Esri
Esri portal For Arcgis |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:06:55.698Z
Reserved: 2024-02-09T19:07:07.977Z
Link: CVE-2024-25698
Updated: 2024-08-01T23:52:05.688Z
Status : Analyzed
Published: 2024-04-04T18:15:11.297
Modified: 2025-01-30T16:18:43.000
Link: CVE-2024-25698
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD