CVE-2024-38039: BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38039?
CVE-2024-38039 is classified as a moderate severity vulnerability due to its potential for HTML injection.
Who is affected by CVE-2024-38039?
CVE-2024-38039 affects users of Esri Portal for ArcGIS versions 11.0 and below.
How do I fix CVE-2024-38039?
To remediate CVE-2024-38039, upgrade Esri Portal for ArcGIS to a version above 11.0.
What types of attacks can CVE-2024-38039 lead to?
CVE-2024-38039 could allow remote, authenticated attackers to execute arbitrary HTML in a victim's browser.
Can CVE-2024-38039 result in data exposure?
CVE-2024-38039 does not lead to stateful changes or compromise customer data directly, but it can facilitate other types of web-based attacks.