Security Advisory

CVE-2024-25707

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-10-04 17:16:47
Last updated 2025-04-10 19:14:34
Assigner Esri
CVSS score 4.8
State PUBLISHED

Description

There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A user cannot be phished into clicking a link to execute code.