A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Esri
Published: 2022-06-28T00:00:00
Updated: 2022-08-16T17:25:13
Reserved: 2022-08-12T00:00:00
Link: CVE-2022-38189
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-08-16T18:15:09.517
Modified: 2022-10-28T12:44:48.270
Link: CVE-2022-38189
JSON object: View
Redhat Information
No data.
CWE