Vulnerability Description
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esri | Portal For Arcgis | <= 11.2 |
Related Weaknesses (CWE)
References
- https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portaVendor Advisory
- https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portaVendor Advisory
FAQ
What is CVE-2024-25695?
CVE-2024-25695 is a vulnerability with a CVSS score of 7.2 (HIGH). There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is ren...
How severe is CVE-2024-25695?
CVE-2024-25695 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-25695?
Check the references section above for vendor advisories and patch information. Affected products include: Esri Portal For Arcgis.