CVE-2024-25709: Self-XSS style in move item dialog
There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could potentially execute arbitrary JavaScript code in a victim’s browser. Exploitation does not require any privileges and can be performed by an anonymous user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25709?
CVE-2024-25709 has been classified as a stored Cross-site Scripting vulnerability.
How do I fix CVE-2024-25709?
To address CVE-2024-25709, update your Esri Portal for ArcGIS to the latest version that includes security patches.
What versions are affected by CVE-2024-25709?
CVE-2024-25709 affects Esri Portal for ArcGIS versions from 10.8.1 to 11.2.
Can CVE-2024-25709 be exploited remotely?
Yes, CVE-2024-25709 can be exploited by a remote, authenticated attacker.
What impact does CVE-2024-25709 have on my system?
CVE-2024-25709 may allow attackers to execute arbitrary JavaScript code within the context of the user's session.