Cross-Site Request Forgery Vulnerability in Esri Portal for ArcGIS
CVE-2023-25832
8.8HIGH
What is CVE-2023-25832?
A cross-site request forgery (CSRF) vulnerability exists in Esri's Portal for ArcGIS that could allow an attacker to manipulate an authorized user into performing unintended commands. This risk poses a significant threat, particularly if successful exploitation leads to further security breaches or information exposure within the affected systems. Users of this platform should apply the necessary updates and patches to safeguard against potential attacks.
Affected Version(s)
Portal for ArcGIS 64 bit All <= 11.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved