CVE-2024-25696: Stored XSS in Portal for ArcGIS
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.0 that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to execute this attack are high.
Other sources
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to execute this attack are high.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25696?
CVE-2024-25696 is classified as a high severity Cross-site Scripting vulnerability.
How do I fix CVE-2024-25696?
To mitigate CVE-2024-25696, upgrade Portal for ArcGIS to version 11.1 or later.
Who can exploit CVE-2024-25696?
CVE-2024-25696 can be exploited by a remote, authenticated attacker with access to the page editor.
What versions are affected by CVE-2024-25696?
CVE-2024-25696 affects Portal for ArcGIS versions 11.0 and earlier.
What kind of attacks are possible with CVE-2024-25696?
CVE-2024-25696 allows attackers to potentially craft links that execute Cross-site Scripting attacks in victim browsers.