CVE-2024-51951

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 79

Summary

CVE-2024-51951 is a stored Cross-site Scripting (XSS) vulnerability affecting ArcGIS Server versions 10.9.1 to 11.3. This issue allows a remote, authenticated attacker with publisher capabilities to craft and share malicious links. Upon clicking the link, a victim's browser could execute arbitrary JavaScript code, leading to potential security risks. The impact of this vulnerability is considered low for both confidentiality and integrity, as it does not directly affect the data itself but rather the user's browser. However, it is crucial to address this issue due to the high privileges required to exploit it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share