BUG-000154662 Reflected XSS vulnerability in Portal for ArcGIS
Vulnerability Description
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25830
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Theologos Kokkinellis
References
More from Esri
View All →Affected Vendor
Esri
View all reports →