Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rj8v-47w4-c66w

Опубликовано: 04 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

EPSS

Процентиль: 50%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

EPSS

Процентиль: 50%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79