Reflected XSS Vulnerability in Esri Portal for ArcGIS
CVE-2022-38188
What is CVE-2022-38188?
A reflected cross-site scripting vulnerability exists in Esri's Portal for ArcGIS version 10.9.1. This flaw allows malicious actors to create specially crafted links that, when clicked by an unsuspecting user, can execute arbitrary JavaScript code in the user's browser. Successful exploitation may lead to various attacks, including data theft, session hijacking, and unauthorized actions on behalf of the user. It's crucial for organizations using this product to implement security patches and educate users about the risks associated with clicking unknown links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Portal for ArcGIS x64 10.9.1
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
