CVE-2021-29107: There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.
Published Jul 10, 2021
·Updated
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.
Affected Software
1 affected component
Esri ArcGIS Server=10.6.1
Event History
Jul 10, 2021
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-29107.
2
What is the severity of CVE-2021-29107?
CVE-2021-29107 has a severity of medium, with a CVSS score of 6.1.
3
How does CVE-2021-29107 affect ArcGIS Server Manager?
CVE-2021-29107 affects ArcGIS Server Manager versions 10.8.1 and below.
4
What is the impact of CVE-2021-29107?
CVE-2021-29107 allows a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.
5
Is there a patch available for CVE-2021-29107?
Yes, a patch for CVE-2021-29107 is available. Please refer to the official reference for more information.