CVE-2024-25695: concatenated errors resulting in cross site scripting and frame injection issues.
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.
Other sources
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25695?
CVE-2024-25695 is classified as a Cross-site Scripting vulnerability with significant security implications.
How do I fix CVE-2024-25695?
To mitigate CVE-2024-25695, update your Esri Portal for ArcGIS software to version 11.3 or later.
Who is affected by CVE-2024-25695?
Any user of Esri Portal for ArcGIS versions 11.2 and below is potentially affected by CVE-2024-25695.
What are the potential impacts of CVE-2024-25695?
CVE-2024-25695 could allow an authenticated attacker to inject malicious scripts into error messages.
Do I need special privileges to exploit CVE-2024-25695?
No, there are no special privileges required to exploit CVE-2024-25695; any authenticated user can potentially execute this attack.