There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.
History

Thu, 10 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Description There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack. There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.

Wed, 08 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
CPEs cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri portal For Arcgis

Tue, 08 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T19:05:16.291Z

Reserved: 2024-02-09T19:07:07.976Z

Link: CVE-2024-25695

cve-icon Vulnrichment

Updated: 2024-08-01T23:52:05.843Z

cve-icon NVD

Status : Modified

Published: 2024-04-04T18:15:10.500

Modified: 2025-04-10T19:15:57.480

Link: CVE-2024-25695

cve-icon Redhat

No data.