Description
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Disable the ArcGIS Portal directory
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23008 | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. |
References
History
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. |
| Metrics |
ssvc
|
Wed, 08 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri portal For Arcgis Linux Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Esri
Esri portal For Arcgis Linux Linux linux Kernel Microsoft Microsoft windows |
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:01:34.842Z
Reserved: 2024-02-09T19:07:07.974Z
Link: CVE-2024-25692
Updated: 2024-08-01T23:52:04.885Z
Status : Modified
Published: 2024-04-04T18:15:09.887
Modified: 2025-04-10T19:15:57.360
Link: CVE-2024-25692
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD