Stored Cross-Site Scripting Vulnerability in ArcGIS Server by Esri
CVE-2024-51951
What is CVE-2024-51951?
ArcGIS Server versions 10.9.1 through 11.3 are susceptible to a stored Cross-Site Scripting vulnerability. An authenticated remote attacker with publisher capabilities may craft a link that, when accessed, executes arbitrary JavaScript code within the victim’s web browser. While the attack requires elevated privileges, it may compromise user safety, as it allows for potential data exposure and integrity issues. Users are advised to apply security updates promptly to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ArcGIS Server Windows all <= 11.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
