There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The privileges required to execute this attack are high.
.This CVE has a CVSS3.1 score of 3.4 and a Base Severity of LOW.
Info | Details |
---|---|
CVE ID | CVE-2023-25840 |
CVE State | PUBLISHED |
BaseScore | 3.4 |
BaseSeverity | LOW |
VectorString | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N |
Version | NA |
References for CVE-2023-25840 :
https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-security-2023-update-1-patch-available/
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NETWORK |
AttackComplexity(AC) | LOW |
PrivilegesRequired(PR) | HIGH |
UserInteraction(UI) | REQUIRED |
Scope(S) | CHANGED |
Confidentiality(C) | NONE |
Availability(A) | NONE |
Integrity(I) | LOW |