CVE-2022-38191: HTML injection vulnerability in Portal for ArcGIS
Published Aug 15, 2022
·Updated
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.
Affected Software
1 affected component
Esri Portal for ArcGIS<=10.9
Event History
Aug 15, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the HTML injection issue in Esri Portal for ArcGIS?
The vulnerability ID is CVE-2022-38191.
2
What is the severity level of CVE-2022-38191?
The severity level of CVE-2022-38191 is medium with a CVSS score of 5.4.
3
Which versions of Esri Portal for ArcGIS are affected by CVE-2022-38191?
Esri Portal for ArcGIS versions 10.9.0 and below are affected by CVE-2022-38191.
4
What can an attacker do with this vulnerability?
A remote, authenticated attacker may be able to inject HTML into some locations in the home application.
5
How can I fix CVE-2022-38191?
To fix CVE-2022-38191, you should apply the security update provided by Esri in their blog post.