Description
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23024 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. |
References
History
Thu, 10 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. |
| Title | Persistent XSS when creating new application using Web App Builder | Persistent XSS when creating new application using Web App Builder |
Thu, 23 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri arcgis Enterprise Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:esri:arcgis_enterprise:10.8.1:*:*:*:*:*:*:* cpe:2.3:a:esri:arcgis_enterprise:10.9.1:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:* |
|
| Vendors & Products |
Esri
Esri arcgis Enterprise Microsoft Microsoft windows |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T18:50:40.932Z
Reserved: 2024-02-09T19:08:35.889Z
Link: CVE-2024-25708
Updated: 2024-08-01T23:52:06.442Z
Status : Modified
Published: 2024-04-04T18:15:13.070
Modified: 2025-04-10T19:15:58.463
Link: CVE-2024-25708
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD