CVE-2024-25701

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 16, 2024
CWE ID 79

Summary

CVE-2024-25701 is a stored Cross-site Scripting (XSS) vulnerability affecting Esri Portal for ArcGIS Enterprise Experience Builder versions 10.8.1 to 11.1. This issue enables a remote, authenticated attacker to create a malicious link containing JavaScript code, which, when loaded in the Experience Builder Embed widget, could execute arbitrary scripts in the victim's browser. Successful exploitation may result in the disclosure of a privileged token, potentially granting the attacker full control of the Portal. The attacker requires high privileges to execute this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Portal for ArcGIS
  • Esri Portal for ArcGIS

Affected Vendors

  • Esri