CVE-2022-38200
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.
Affected (2)
Products: Esri: Arcgis Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.7.1 |
References (2)
Source: psirt@esri.com
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.