| |
Vulnerability CVE-2024-25692
Published: 2024-04-04
| Description: |
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.
|
Type:
CWE-352 (Cross-Site Request Forgery (CSRF))
References: |
https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2/
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|