← Retour aux CVEs
CVE-2023-25840
LOW3.4
Description
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The privileges required to execute this attack are high.
Details CVE
Score CVSS v3.13.4
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurREQUIRED
Publie7/21/2023
Derniere modification4/10/2025
Sourcenvd
Observations honeypot0
Produits affectes
esri:arcgis_serverlinux:linux_kernelmicrosoft:windows
Faiblesses (CWE)
CWE-79
References
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.