Vulnerability Details CVE-2024-25692
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-25692
-
cpe:2.3:a:esri:portal_for_arcgis:-
-
cpe:2.3:a:esri:portal_for_arcgis:10.6
-
cpe:2.3:a:esri:portal_for_arcgis:10.6.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.7.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.8
-
cpe:2.3:a:esri:portal_for_arcgis:10.8.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.9
-
cpe:2.3:a:esri:portal_for_arcgis:10.9.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.0
-
cpe:2.3:a:esri:portal_for_arcgis:11.1
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-