Lucene search

K
nvd[email protected]NVD:CVE-2024-25697
HistoryApr 04, 2024 - 6:15 p.m.

CVE-2024-25697

2024-04-0418:15:11
CWE-79
web.nvd.nist.gov
3
cross-site scripting
portal for arcgis
cve-2024-25697
vulnerability
authenticated attacker
crafted link
image rendering
low privileges

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

There is a Cross-site Scripting vulnerabilityย in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. ย The privileges required to execute this attack are low.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2024-25697