CVE-2024-25697: Stored XSS in Portal for ArcGIS
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low.
Other sources
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25697?
CVE-2024-25697 is classified as a Cross-site Scripting vulnerability with potential exploitation risks.
How do I fix CVE-2024-25697?
To fix CVE-2024-25697, upgrade to Portal for ArcGIS version 11.2 or later.
Who is affected by CVE-2024-25697?
CVE-2024-25697 affects users of Portal for ArcGIS running version 11.1 or earlier.
What version of Portal for ArcGIS is vulnerable to CVE-2024-25697?
Portal for ArcGIS versions 11.1 and earlier are vulnerable to CVE-2024-25697.
Can CVE-2024-25697 be exploited remotely?
Yes, CVE-2024-25697 can be exploited remotely by authenticated attackers.