First published: Tue Jun 28 2022(Updated: )
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | <=10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38192 is a stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS.
CVE-2022-38192 allows a remote, authenticated attacker to pass and store malicious strings in crafted queries, which could potentially execute arbitrary JavaScript code in the user's browser.
CVE-2022-38192 has a severity level of medium (5.4).
To fix CVE-2022-38192, apply the security update provided by Esri. More details can be found in the reference link.
You can find more information about CVE-2022-38192 in the reference link provided.