Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5w6r-7h9g-pfhr

Опубликовано: 21 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.

There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.

EPSS

Процентиль: 46%
0.0023
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.

EPSS

Процентиль: 46%
0.0023
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79