cve/2023/CVE-2023-25841.md
2024-05-25 21:48:12 +02:00

958 B
Raw Blame History

CVE-2023-25841

Description

There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 11.0 on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victims browser.Mitigation: Disable anonymous access to ArcGIS Feature services with edit capabilities.

POC

Reference

No PoCs from references.

Github