HTML Injection Vulnerability in Esri Portal for ArcGIS
CVE-2023-25833

5.4MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
10 May 2023

What is CVE-2023-25833?

An HTML injection vulnerability exists in Esri Portal for ArcGIS, affecting versions 11.0 and earlier. This flaw allows authenticated remote attackers to generate specially crafted links capable of rendering arbitrary HTML in unsuspecting users' browsers. Although no changes to the state or customer data occur, this vulnerability poses risks as it could facilitate phishing attacks or the execution of malicious scripts within a user’s session.

Affected Version(s)

Portal for ArcGIS 64 bit All <= 11.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.