Vulnerability Details CVE-2024-25709
There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could potentially execute arbitrary JavaScript code in a victim’s browser. Exploitation does not require any privileges and can be performed by an anonymous user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.2%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-25709
-
cpe:2.3:a:esri:portal_for_arcgis:10.8.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.9.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.0
-
cpe:2.3:a:esri:portal_for_arcgis:11.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.2
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-