CVE-2022-38207: Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-38207.
What is the affected software?
The affected software is Esri Portal for ArcGIS versions 10.8.1 and 10.7.1.
What is the severity of CVE-2022-38207?
The severity of CVE-2022-38207 is medium with a CVSS score of 6.1.
How does CVE-2022-38207 work?
CVE-2022-38207 is a reflected XSS vulnerability that allows a remote unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim's browser.
How can I fix CVE-2022-38207?
To fix CVE-2022-38207, it is recommended to apply the security update or patch provided by Esri, which can be found at the reference link.