TROYANOSYVIRUS
Volver a CVEs

CVE-2023-25840

LOW
3.4

Descripcion

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.

Detalles CVE

Puntuacion CVSS v3.13.4
SeveridadLOW
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioREQUIRED
Publicado7/21/2023
Ultima modificacion4/10/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

esri:arcgis_serverlinux:linux_kernelmicrosoft:windows

Debilidades (CWE)

CWE-79

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.