CVE-2024-38039
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 79
CWE ID 80
Summary
CVE-2024-38039 is a recently disclosed vulnerability affecting Esri Portal for ArcGIS versions 11.0 and below. This issue permits a remote, authenticated attacker to inject malicious HTML code into the portal, causing arbitrary HTML to be rendered in the victim's browser. While no customer data is exposed or stateful changes are made, the vulnerability can lead to potential phishing or redirection attacks, posing a significant security risk. Esri strongly recommends users upgrade to a patched version of the software to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Esri Portal for ArcGIS
- Portal for ArcGIS
Affected Vendors
- Esri