ZeroHour

CVE-2022-38200

CVSS 3.1
6.1 medium
EPSS
<1%p28
Published
()
Modified
Description

A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.

Vendors
esri
Products
arcgis server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.