Impact
The vulnerability is a stored cross‑site scripting flaw in Esri Portal for ArcGIS versions 11.5 and earlier. It permits a remote, privileged attacker to inject malicious code that is stored in the platform. When another user views the stored content, the code executes in the victim’s browser. This can lead to theft of credentials, session hijacking, or other malicious client‑side actions.
Affected Systems
Affected systems include Esri Portal for ArcGIS 11.5 and older, specifically ArcGIS Enterprise 11.1, 11.3, and 11.5. Users of those releases should be aware that any content created or edited by privileged accounts is stored without proper sanitization.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium‑impact risk. Because the attack requires a privileged account to inject the payload, the threat is limited to environments where attackers have elevated access. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so there is no known widespread exploitation, but the lack of an EPSS rating makes the exact exploitation frequency uncertain.
OpenCVE Enrichment