First published: Tue May 09 2023(Updated: )
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
Credit: psirt@esri.com psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | <=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2023-25832.
The severity level of CVE-2023-25832 is high with a CVSS score of 8.8.
The affected software for CVE-2023-25832 is Esri Portal for ArcGIS Versions 11.0 and below.
An attacker can exploit CVE-2023-25832 by tricking an authorized user into executing unwanted actions through cross-site request forgery.
To mitigate the vulnerability in CVE-2023-25832, it is recommended to apply the security patch provided by Esri.