Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23023 | There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A user cannot be phished into clicking a link to execute code. |
Tue, 15 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri portal For Arcgis |
|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Esri
Esri portal For Arcgis |
|
| Metrics |
ssvc
|
Fri, 04 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A user cannot be phished into clicking a link to execute code. | |
| Title | BUG-000160241 - Reflected XSS in Portal for ArcGIS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:14:34.300Z
Reserved: 2024-02-09T19:08:35.888Z
Link: CVE-2024-25707
Updated: 2024-10-04T18:55:33.818Z
Status : Analyzed
Published: 2024-10-04T18:15:06.790
Modified: 2024-10-15T14:34:43.597
Link: CVE-2024-25707
No data.
OpenCVE Enrichment
No data.
EUVD