There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.0 that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to execute this attack are high.
History

Wed, 08 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
CPEs cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri portal For Arcgis

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2024-10-08T16:38:59.045Z

Reserved: 2024-02-09T19:07:07.976Z

Link: CVE-2024-25696

cve-icon Vulnrichment

Updated: 2024-08-01T23:52:06.106Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T18:15:10.757

Modified: 2025-01-08T14:30:29.987

Link: CVE-2024-25696

cve-icon Redhat

No data.