CVE-2023-25832: BUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.
Published May 9, 2023
·Updated
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
Affected Software
1 affected component
Esri Portal for ArcGIS<=11.0
Event History
May 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-25832.
2
What is the severity level of CVE-2023-25832?
The severity level of CVE-2023-25832 is high with a CVSS score of 8.8.
3
What is the affected software for CVE-2023-25832?
The affected software for CVE-2023-25832 is Esri Portal for ArcGIS Versions 11.0 and below.
4
How can an attacker exploit CVE-2023-25832?
An attacker can exploit CVE-2023-25832 by tricking an authorized user into executing unwanted actions through cross-site request forgery.
5
How can I mitigate the vulnerability in CVE-2023-25832?
To mitigate the vulnerability in CVE-2023-25832, it is recommended to apply the security patch provided by Esri.