CVE-2022-38188: XSS
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the reflected XSS vulnerability in Esri Portal for ArcGIS?
The vulnerability ID for the reflected XSS vulnerability in Esri Portal for ArcGIS is CVE-2022-38188.
What is the severity of CVE-2022-38188?
The severity of CVE-2022-38188 is high with a CVSS score of 6.1.
Which versions of Esri Portal for ArcGIS are affected by CVE-2022-38188?
Esri Portal for ArcGIS versions up to and including 10.8.1 are affected by CVE-2022-38188.
How can a remote attacker exploit CVE-2022-38188?
A remote attacker can exploit CVE-2022-38188 by convincing a user to click on a crafted link, which may execute arbitrary JavaScript code in the victim's browser.
Is there a patch available for CVE-2022-38188?
Yes, a patch is available for CVE-2022-38188. Please refer to the following link for more information: [Link to patch](https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2022-update-1-patch/)