Skip to content

CVE-2023-25840 | Server

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high. .This CVE has a CVSS3.1 score of 3.4 and a Base Severity of LOW.

InfoDetails
CVE IDCVE-2023-25840
CVE StatePUBLISHED
BaseScore3.4
BaseSeverityLOW
VectorStringCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
VersionNA

References for CVE-2023-25840 :
https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-security-2023-update-1-patch-available/

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)HIGH
UserInteraction(UI)REQUIRED
Scope(S)CHANGED
Confidentiality(C)NONE
Availability(A)NONE
Integrity(I)LOW