CVE-2024-25705
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. Exploitation requires basic authenticated access but does not require elevated or administrative privileges, indicating low privileges are required.
Affected (1)
Products: Esri: Portal For Arcgis
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
References (1)
Timeline
No history available yet.