Security Advisory

CVE-2024-25700

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-04-04 17:55:01
Last updated 2025-05-12 15:19:11
Assigner Esri
CVSS score 4.8
State PUBLISHED

Description

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in a web map link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high.