There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
History

Tue, 08 Oct 2024 17:00:00 +0000

Type Values Removed Values Added
Description This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is scheduled to be patched at a future time. There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
Title HTMLi at createFolder Content Injection
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published: 2024-04-04T17:55:30.732Z

Updated: 2024-10-08T16:41:51.121Z

Reserved: 2024-02-09T19:08:35.888Z

Link: CVE-2024-25706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-04T18:15:12.830

Modified: 2024-10-10T12:57:21.987

Link: CVE-2024-25706

cve-icon Redhat

No data.