CVE-2024-38039

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 79
CWE ID 80

Summary

CVE-2024-38039 is a recently disclosed vulnerability affecting Esri Portal for ArcGIS versions 11.0 and below. This issue permits a remote, authenticated attacker to inject malicious HTML code into the portal, causing arbitrary HTML to be rendered in the victim's browser. While no customer data is exposed or stateful changes are made, the vulnerability can lead to potential phishing or redirection attacks, posing a significant security risk. Esri strongly recommends users upgrade to a patched version of the software to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS
  • Portal for ArcGIS

Affected Vendors

  • Esri