4.8
CVE-2025-57873
- EPSS 0.02%
- Veröffentlicht 29.09.2025 19:15:36
- Zuletzt bearbeitet 17.10.2025 14:14:40
- Quelle psirt@esri.com
- CVE-Watchlists
- Unerledigt
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Esri ≫ Portal For Arcgis Version10.9.1 Update-
Esri ≫ Portal For Arcgis Version10.9.1 Updatesecurity_2025_update1
Esri ≫ Portal For Arcgis Version10.9.1 Updatesecurity_2025_update2
Esri ≫ Portal For Arcgis Version11.0
Esri ≫ Portal For Arcgis Version11.1 Update-
Esri ≫ Portal For Arcgis Version11.1 Updatesecurity_2024_update1
Esri ≫ Portal For Arcgis Version11.1 Updatesecurity_2024_update2
Esri ≫ Portal For Arcgis Version11.1 Updatesecurity_2025_update1
Esri ≫ Portal For Arcgis Version11.1 Updatesecurity_2025_update2
Esri ≫ Portal For Arcgis Version11.2 Update-
Esri ≫ Portal For Arcgis Version11.2 Updatesecurity_2024_update1
Esri ≫ Portal For Arcgis Version11.2 Updatesecurity_2024_update2
Esri ≫ Portal For Arcgis Version11.2 Updatesecurity_2025_update1
Esri ≫ Portal For Arcgis Version11.2 Updatesecurity_2025_update2
Esri ≫ Portal For Arcgis Version11.3 Update-
Esri ≫ Portal For Arcgis Version11.3 Updatesecurity_2025_update1
Esri ≫ Portal For Arcgis Version11.3 Updatesecurity_2025_update2
Esri ≫ Portal For Arcgis Version11.4 Update-
Esri ≫ Portal For Arcgis Version11.4 Updatesecurity_2025_update1
Esri ≫ Portal For Arcgis Version11.4 Updatesecurity_2025_update2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@esri.com | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.