CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2024-25706
Severity
MEDIUM
CVSS
6.1
EPSS
0.43%
Original NVD Description
There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)