First published: Wed Jul 19 2023(Updated: )
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
Credit: psirt@esri.com psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS Insights | =2022.1 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25839 is a SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database.
CVE-2023-25839 has a severity level of high (7).
Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 is affected by CVE-2023-25839.
An attacker can exploit CVE-2023-25839 by generating crafted input to execute arbitrary SQL commands against the back-end database.
More information about CVE-2023-25839 can be found at the following link: [Esri ArcGIS Insights Security Patches](https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-insights-security-patches-for-arcgis-insights-2022-1-are-now-available/)