Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25697

Опубликовано: 04 апр. 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Версия до 11.1 (включая)

EPSS

Процентиль: 50%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
почти 2 года назад

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

EPSS

Процентиль: 50%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79