There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
History

Thu, 10 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
Description There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.  There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Title Persistent XSS when creating new application using Web App Builder Persistent XSS when creating new application using Web App Builder

Thu, 23 Jan 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Enterprise
Microsoft
Microsoft windows
CPEs cpe:2.3:a:esri:arcgis_enterprise:10.8.1:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_enterprise:10.9.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*
Vendors & Products Esri
Esri arcgis Enterprise
Microsoft
Microsoft windows

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T18:50:40.932Z

Reserved: 2024-02-09T19:08:35.889Z

Link: CVE-2024-25708

cve-icon Vulnrichment

Updated: 2024-08-01T23:52:06.442Z

cve-icon NVD

Status : Modified

Published: 2024-04-04T18:15:13.070

Modified: 2025-04-10T19:15:58.463

Link: CVE-2024-25708

cve-icon Redhat

No data.