CVE-2024-8149

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Jan 30, 2025
CWE ID 79

Summary

CVE-2024-8149 is a reflected XSS (Cross-Site Scripting) vulnerability affecting Esri Portal for ArcGIS versions 11.1 and 11.2. An attacker can craft a malicious link that, when clicked, could inject and execute arbitrary JavaScript code in a victim's web browser, potentially leading to data theft or unauthorized actions. This issue poses a significant risk, as it does not require authentication for exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS

Affected Vendors

  • Esri