CVE-2024-25707

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 79

Summary

CVE-2024-25707 is a reflected cross-site scripting (XSS) vulnerability affecting Esri Portal for ArcGIS versions 11.1 and below on Windows and Linux x64. This issue allows a remote, authenticated attacker with administrative access to inject malicious JavaScript code into the platform through a specially crafted input. Although Self XSS means the user initiates the attack, it could still lead to serious security consequences, underscoring the importance of addressing this vulnerability promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS
  • Portal for ArcGIS

Affected Vendors

  • Esri