First published: Thu Apr 04 2024(Updated: )
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25697 is classified as a Cross-site Scripting vulnerability with potential exploitation risks.
To fix CVE-2024-25697, upgrade to Portal for ArcGIS version 11.2 or later.
CVE-2024-25697 affects users of Portal for ArcGIS running version 11.1 or earlier.
Portal for ArcGIS versions 11.1 and earlier are vulnerable to CVE-2024-25697.
Yes, CVE-2024-25697 can be exploited remotely by authenticated attackers.