CVE-2024-25700: Persistent XSS in URL added to a shared map
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in a web map link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25700?
CVE-2024-25700 has been rejected and does not have a severity rating because it is scheduled to be patched at a future time.
How do I fix CVE-2024-25700?
To mitigate CVE-2024-25700, it is recommended to upgrade to the patched version of Esri Portal for ArcGIS Enterprise Web App Builder once it is released.
Which versions of Esri Portal for ArcGIS Enterprise Web App Builder are affected by CVE-2024-25700?
CVE-2024-25700 affects versions of Esri Portal for ArcGIS Enterprise Web App Builder up to and including version 11.1.
What type of vulnerability is CVE-2024-25700?
CVE-2024-25700 is classified as a stored Cross-site Scripting vulnerability.
Is there any workaround for CVE-2024-25700?
As CVE-2024-25700 is currently unaddressed due to its rejection, specific workarounds are not provided.