CVE-2022-38201: An unvalidated redirect vulnerability exists in Esri ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1.
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38201?
CVE-2022-38201 is an unvalidated redirect vulnerability in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1.
What is the severity of CVE-2022-38201?
The severity of CVE-2022-38201 is medium with a CVSS score of 6.1.
How does CVE-2022-38201 impact Esri Portal for ArcGIS Quick Capture Web Designer?
CVE-2022-38201 can potentially allow a remote, unauthenticated attacker to redirect an unsuspecting authenticated user to an attacker-controlled domain.
Which versions of Esri Portal for ArcGIS Quick Capture Web Designer are affected by CVE-2022-38201?
Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1 are affected by CVE-2022-38201.
How can I fix CVE-2022-38201?
It is recommended to apply the security patch provided by Esri. Please refer to the official Esri blog for more information.