Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29f2-5rg5-fpqh

Опубликовано: 17 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

EPSS

Процентиль: 81%
0.01658
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.

CVSS3: 6.1
fstec
около 3 лет назад

Уязвимость веб-портала Portal for ArcGIS, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 81%
0.01658
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94