CVE-2024-25690: HTML injection in ArcGIS Web AppBuilder
Published Apr 4, 2024
·Updated
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
Affected Software
3 affected components
All of the following
Esri Portal for ArcGIS<=11.1
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 4, 2024
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25690?
CVE-2024-25690 has a high severity rating due to its potential to allow remote attackers to execute arbitrary HTML.
2
How do I fix CVE-2024-25690?
To fix CVE-2024-25690, upgrade to a version of Esri Portal for ArcGIS that is higher than 11.1.
3
Who is affected by CVE-2024-25690?
CVE-2024-25690 affects all users of Esri Portal for ArcGIS versions 11.1 and below.
4
What type of attack does CVE-2024-25690 enable?
CVE-2024-25690 enables an HTML injection attack that can be triggered through crafted links.
5
Is CVE-2024-25690 present in newer versions of the software?
No, CVE-2024-25690 is not present in Esri Portal for ArcGIS versions above 11.1, as these versions contain security fixes.