Vulnerabilities (CVE)

Filtered by vendor Esri Subscribe
Filtered by product Portal For Arcgis
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25837 1 Esri 1 Portal For Arcgis 2023-11-30 N/A 4.8 MEDIUM
There is a Cross-site Scripting vulnerability in Esri ArcGIS Enterprise Sites versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked by a victim could potentially execute arbitrary JavaScript code in the target's browser.  The privileges required to execute this attack are high.   
CVE-2023-25835 1 Esri 1 Portal For Arcgis 2023-11-30 N/A 4.8 MEDIUM
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in the site configuration which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.  
CVE-2023-25836 1 Esri 1 Portal For Arcgis 2023-08-07 N/A 5.4 MEDIUM
There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.
CVE-2021-29110 1 Esri 1 Portal For Arcgis 2022-02-28 3.5 LOW 5.4 MEDIUM
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
CVE-2021-29109 1 Esri 1 Portal For Arcgis 2022-02-28 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.