CVE-2022-38210: HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only)
Published Dec 29, 2022
·Updated
There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
Affected Software
1 affected component
Esri Portal for ArcGIS<=10.9.1
Event History
Dec 29, 2022
CVE Published
08:15 PM
Dec 30, 2022
CVE Published
via MITRE·05:13 AM
Data Sourced
via MITRE·05:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-38210.
2
What is the title of this vulnerability?
The title of this vulnerability is 'There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below.'
3
What is the severity of CVE-2022-38210?
The severity of CVE-2022-38210 is medium.
4
How does CVE-2022-38210 affect Esri Portal for ArcGIS?
CVE-2022-38210 affects Esri Portal for ArcGIS versions 10.9.1 and below.
5
How can an attacker exploit CVE-2022-38210?
An attacker can exploit CVE-2022-38210 by creating a crafted link that, when clicked, could render arbitrary HTML in the victim's browser.