First published: Mon Dec 30 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS | =10.1 | |
Esri ArcGIS | =10.2 | |
ESRI ArcGIS for Server | =10.1 | |
ESRI ArcGIS for Server | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7231 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2013-7231, it is recommended to apply the latest patches provided by Esri for ArcGIS versions 10.1 and 10.2.
CVE-2013-7231 affects users of Esri ArcGIS and ArcGIS Server versions 10.1 and 10.2.
CVE-2013-7231 can enable remote authenticated users to conduct cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
No, CVE-2013-7231 is a different vulnerability than CVE-2013-5222, though both involve the Mobile Content Server in ArcGIS.