ZeroHour

CVE-2023-25840

CVSS 3.1
3.4 low
EPSS
<1%p40
Published
()
Modified
Description

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The privileges required to execute this attack are high.

Vendors
esri
Products
arcgis server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.