CVE-2024-25692: BUG-000154722 - Cross-site request forgery (CSRF) issue in Portal for ArcGIS
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25692?
CVE-2024-25692 is classified as a cross-site request forgery vulnerability with a potential risk for unauthorized actions.
How do I fix CVE-2024-25692?
To mitigate CVE-2024-25692, ensure you upgrade to Esri Portal for ArcGIS version 11.2 or later.
Who is affected by CVE-2024-25692?
CVE-2024-25692 affects users of Esri Portal for ArcGIS version 11.1 and below.
Can CVE-2024-25692 be exploited remotely?
Yes, CVE-2024-25692 can be exploited remotely by an attacker who tricks an authorized user into submitting a malicious request.
What actions can an attacker perform with CVE-2024-25692?
An attacker exploiting CVE-2024-25692 may execute unwanted actions on behalf of the authenticated user.