5.4
CVSSv3

CVE-2023-25833

Published: 10/05/2023 Updated: 01/02/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated malicious user to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

esri portal for arcgis