BUG-000157278 – ArcGIS Insights has a security vulnerability - desktop
CVE-2023-25839
7HIGH
What is CVE-2023-25839?
An SQL injection vulnerability exists in Esri ArcGIS Insights Desktop for both Mac and Windows platforms, specifically in version 2022.1. This flaw permits a local, authorized attacker to potentially execute arbitrary SQL commands against the underlying database. The exploitation of this vulnerability requires a complex process of crafting specific input, demanding significant effort for the attacker to achieve a successful outcome.
Affected Version(s)
ArcGIS Insights 64 bit 2022.1