Esri ArcGIS Enterprise是美国环境系统研究所(Esri)公司的一套GIS(地理信息系统)的基础软件系统。该系统支持制图和可视化、分析以及数据管理等。 Esri ArcGIS Enterprise 10.8.1至10.9版本存在跨站脚本漏洞,该漏洞源于于存在跨站脚本(XSS)漏洞。攻击可利用该漏洞诱导用户点击恶意链接,并在受害者浏览器中执行任意JavaScript代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Esri | Portal for ArcGIS Sites | All ~ 10.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25841 | 6.1 MEDIUM | BUG-000158075 Stored XSS issue in ArcGIS Server |
| CVE-2023-25836 | 5.4 MEDIUM | BUG-000135364 XSS in 10.8.1 sites builder iframe source |
| CVE-2023-25840 | 3.4 LOW | BUG-000154070 Stored XSS issue in the ArcGIS REST Services directory |
No comments yet