There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.
History

Wed, 08 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
CPEs cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri portal For Arcgis

Tue, 08 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2024-10-08T16:38:33.749Z

Reserved: 2024-02-09T19:07:07.976Z

Link: CVE-2024-25695

cve-icon Vulnrichment

Updated: 2024-08-01T23:52:05.843Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T18:15:10.500

Modified: 2025-01-08T14:32:59.223

Link: CVE-2024-25695

cve-icon Redhat

No data.