Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious scripts into Esri Portal for ArcGIS. When a victim’s browser renders the affected content, the injected script can execute arbitrary code within the victim’s browser context. Based on the description, the likely attack vector is from a remote source that has administrative privileges within the portal, although this is not explicitly stated in the advisory and is therefore inferred.
Affected Systems
Esri Portal for ArcGIS versions 11.5 and earlier, specifically 11.1, 11.3, and 11.5, are affected. All ArcGIS Enterprise deployments up to version 11.5 should be considered vulnerable until they are patched or upgraded to the latest long‑term support release.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The vulnerability requires remote interaction with the portal but only from users possessing administrative rights. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, so the likelihood of exploitation is considered moderate. Because the advisory specifies remote, administratively privileged access as a prerequisite, that is the inferred attack vector, but no public exploits are reported.
OpenCVE Enrichment