CVE-2013-5222: XSS
Published Dec 30, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Esri ArcGIS=10.1
Esri ArcGIS Server=10.1
Event History
Dec 30, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5222?
CVE-2013-5222 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-5222?
To fix CVE-2013-5222, apply the latest patches or updates from ESRI for ArcGIS Server 10.1.
3
What types of attacks can CVE-2013-5222 lead to?
CVE-2013-5222 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
4
Who is affected by CVE-2013-5222?
Remote authenticated users of ESRI ArcGIS for Server 10.1 are affected by CVE-2013-5222.
5
Can CVE-2013-5222 be exploited without authentication?
No, CVE-2013-5222 requires remote authenticated users to exploit the vulnerability.