Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown

CVE-2024-25694

Disclosure Date: October 04, 2024 (last updated October 17, 2024)
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in the Layer Showcase application configuration which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.
Attacker Value
Unknown

CVE-2024-25691

Disclosure Date: October 04, 2024 (last updated October 16, 2024)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1, 10.9.1 and 10.8.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2024-25709

Disclosure Date: April 04, 2024 (last updated February 01, 2025)
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS versions 10.8.1 – 1121 that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item which will potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Attacker Value
Unknown

CVE-2024-25706

Disclosure Date: April 04, 2024 (last updated January 12, 2025)
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
Attacker Value
Unknown

CVE-2024-25705

Disclosure Date: April 04, 2024 (last updated February 06, 2025)
There is a cross site scripting vulnerability in the Esri Portal for ArcGIS Experience Builder 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are low.
Attacker Value
Unknown

CVE-2024-25699

Disclosure Date: April 04, 2024 (last updated January 31, 2025)
There is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 through 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially allow a remote, unauthenticated attacker to compromise the confidentiality, integrity, and availability of the software.
Attacker Value
Unknown

CVE-2024-25698

Disclosure Date: April 04, 2024 (last updated January 31, 2025)
There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2024-25697

Disclosure Date: April 04, 2024 (last updated January 12, 2025)
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.
Attacker Value
Unknown

CVE-2024-25696

Disclosure Date: April 04, 2024 (last updated January 12, 2025)
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.0 that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to execute this attack are high.
Attacker Value
Unknown

CVE-2024-25695

Disclosure Date: April 04, 2024 (last updated January 12, 2025)
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.