Description
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8... https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8095
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29721 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered). |
References
History
Thu, 10 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | BUG-000155004 HTML injection issue in Portal for ArcGIS. |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T18:40:10.575Z
Reserved: 2023-02-15T00:00:00.000Z
Link: CVE-2023-25833
No data.
Status : Modified
Published: 2023-05-10T02:15:08.933
Modified: 2024-11-21T07:50:17.503
Link: CVE-2023-25833
No data.
OpenCVE Enrichment
No data.
EUVD