Cross-Site Scripting Vulnerability in ESRI Enterprise Products
CVE-2021-3012

5.4MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
8 April 2021

What is CVE-2021-3012?

A cross-site scripting vulnerability exists in ESRI Enterprise products prior to version 10.9. This flaw enables remote authenticated users to exploit the system by injecting arbitrary JavaScript code through the Document Link feature. Specifically, a malicious HTML attribute, such as onerror, in the URL field of the Parameters tab can be utilized for this injection, potentially compromising the security of the affected applications.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.