CVE-2024-25707
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 79
Summary
CVE-2024-25707 is a reflected cross-site scripting (XSS) vulnerability affecting Esri Portal for ArcGIS versions 11.1 and below on Windows and Linux x64. This issue allows a remote, authenticated attacker with administrative access to inject malicious JavaScript code into the platform through a specially crafted input. Although Self XSS means the user initiates the attack, it could still lead to serious security consequences, underscoring the importance of addressing this vulnerability promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Esri Portal for ArcGIS
- Portal for ArcGIS
Affected Vendors
- Esri