TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-25840

LOW
3.4

Description

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.

Details CVE

Score CVSS v3.13.4
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurREQUIRED
Publie7/21/2023
Derniere modification4/10/2025
Sourcenvd
Observations honeypot0

Produits affectes

esri:arcgis_serverlinux:linux_kernelmicrosoft:windows

Faiblesses (CWE)

CWE-79

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.