First published: Thu Apr 04 2024(Updated: )
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | <=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25706 is considered a high-severity vulnerability due to its potential for HTML injection leading to phishing attacks.
To fix CVE-2024-25706, it is recommended to update Esri Portal for ArcGIS to version 11.1 or later.
CVE-2024-25706 affects all versions of Esri Portal for ArcGIS up to and including version 11.0.
CVE-2024-25706 facilitates HTML injection attacks that can lead to phishing attempts against users.
No, CVE-2024-25706 can be exploited by remote, unauthenticated attackers.