CVE Published: 07/12/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: Esri |
Vendor: Esri |
Product: ArcGIS Server Status : PUBLISHED
CVE-2021-29116 Description
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.