Impact
A stored cross‑site scripting flaw exists in Esri Portal for ArcGIS versions 11.5 and earlier, allowing a remote attacker with privileged access to inject malicious script that is subsequently served to other users. The malicious code could execute arbitrary instructions within the victim’s browser, potentially compromising the user’s session or defacing the application. This weakness corresponds to CWE‑79, reflecting insufficient input validation before rendering.
Affected Systems
Esri Portal for ArcGIS versions 11.5 and earlier, notably the 11.1, 11.3, and 11.5 releases, are affected. Users of ArcGIS Enterprise running these releases must update or upgrade to remain safe.
Risk and Exploitability
With a CVSS score of 6.1, the vulnerability carries medium severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, web‑based, and requires the attacker to possess privileged access to inject persisted payloads. Because it is an XSS flaw, the impact is limited to the browsers of authenticated or unauthenticated users who view the stored content, but it can lead to session hijacking or defacement if exploited.
OpenCVE Enrichment