Cross Frame Scripting Vulnerability in ArcGIS Enterprise by Esri
CVE-2019-16193

5.4MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
11 September 2019

What is CVE-2019-16193?

ArcGIS Enterprise version 10.6.1 is susceptible to Cross Frame Scripting (XFS) attacks. This vulnerability is triggered through a specially crafted IFRAME element within the 'EDIT MY PROFILE' feature, allowing attackers to potentially exploit the application and compromise user data. It is crucial for organizations using ArcGIS Enterprise to address this vulnerability to maintain the integrity and security of their operations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.