Lucene search

K
cvelistEsriCVELIST:CVE-2024-25690
HistoryApr 04, 2024 - 5:53 p.m.

CVE-2024-25690 HTML injection in ArcGIS Web AppBuilder

2024-04-0417:53:03
CWE-80
Esri
www.cve.org
2
cve-2024-25690
html injection
arcgis web appbuilder
esri portal
vulnerability
remote attack
unauthenticated
crafted link
render html

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows",
      "Linux"
    ],
    "product": "ArcGIS Enterprise Web App Builder",
    "vendor": "Esri",
    "versions": [
      {
        "lessThanOrEqual": "<=11.1",
        "status": "affected",
        "version": "all",
        "versionType": "11.1"
      }
    ]
  }
]

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2024-25690