CyberRota Analysis
AI-GeneratedEsri Portal for ArcGIS versions 11.5 and earlier are vulnerable to a stored cross-site scripting (XSS) issue, allowing an attacker with administrative privileges to inject malicious code that may execute in a victim's browser. This vulnerability poses a medium risk, particularly for organizations utilizing ArcGIS Enterprise versions 11.1, 11.3, and 11.5, which should prioritize patching to mitigate potential exploitation. All users are advised to upgrade to the latest long-term support release to enhance security.
Original NVD Description
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Related CVEs
Other vulnerabilities affecting the same vendor(s)