CVE-2024-25705: Cross site scripting issue in embed widget
There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. Exploitation requires basic authenticated access but does not require elevated or administrative privileges, indicating low privileges are required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25705?
CVE-2024-25705 has been classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2024-25705?
To fix CVE-2024-25705, upgrade Esri Portal for ArcGIS Experience Builder to version 11.2 or later.
Who is affected by CVE-2024-25705?
CVE-2024-25705 affects users of Esri Portal for ArcGIS Experience Builder version 11.1 and below on both Windows and Linux platforms.
What type of attack does CVE-2024-25705 facilitate?
CVE-2024-25705 facilitates cross-site scripting attacks that allow remote, unauthenticated attackers to execute arbitrary JavaScript.
Can CVE-2024-25705 be exploited without user interaction?
Yes, CVE-2024-25705 can be exploited by creating a crafted link that executes malicious code when clicked by a user.