Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-8148

Disclosure Date: October 04, 2024 (last updated January 31, 2025)
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 10.8.1 - 11.2 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Attacker Value
Unknown

CVE-2024-38038

Disclosure Date: October 04, 2024 (last updated October 16, 2024)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2024-38036

Disclosure Date: October 04, 2024 (last updated December 21, 2024)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2024-25691

Disclosure Date: October 04, 2024 (last updated October 16, 2024)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1, 10.9.1 and 10.8.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2024-25709

Disclosure Date: April 04, 2024 (last updated February 01, 2025)
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS versions 10.8.1 – 1121 that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item which will potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.
Attacker Value
Unknown

CVE-2023-25831

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2023-25830

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38207

Disclosure Date: December 05, 2022 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38204

Disclosure Date: December 05, 2022 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38194

Disclosure Date: June 28, 2022 (last updated October 08, 2023)
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.