Aller au contenu

Fiche vulnérabilité

CVE-2024-25695 : faille élevée esri portal for arcgis (CVSS 7.2)

Description

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
4 avr. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • esri portal for arcgis

Références

Rechercher une autre vulnérabilité dans la base CVE