CVE Published: 21/07/2023 |
CVE Updated: 08/10/2024 |
CVE Year: 2023 Source: Esri |
Vendor: Esri |
Product: ArcGIS Enterprise Server Status : PUBLISHED
CVE-2023-25840 Description
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The privileges required to execute this attack are high.
Metrics
CVSS Version: 3.1 |
Base Score: 3.4 LOW Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N