CVE-2024-25692

CVSS V2 None CVSS V3 None
Description
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. 
Overview
  • CVE ID
  • CVE-2024-25692
  • Assigner
  • Esri
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-04T17:51:48.127Z
  • Last Modified Date
  • 2024-04-19T22:28:02.403Z
History
Created Old Value New Value Data Type Notes
2024-06-26 12:28:43 Added to TrackCVE