Cross-Site Request Forgery Vulnerability in ArcGIS Versions 11.1 and Below
CVE-2024-25692
What is CVE-2024-25692?
A cross-site request forgery vulnerability exists in Esri Portal for ArcGIS that may allow a remote, unauthenticated attacker to manipulate actions taken by an authorized user. By crafting specific forms, the attacker can potentially trick users into executing unintended commands without their knowledge. The vulnerability primarily affects versions 11.1 and earlier of the software, impacting its web application security framework. Although the direct effects on confidentiality and integrity are limited, users are encouraged to apply the necessary updates to mitigate any associated security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Portal for ArcGIS Windows all <= 11.0
References
CVSS V3.1
Timeline
Vulnerability published
