漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
XSS issue is Esri ArcGIS Pro versions 3.6.0 and earlier
Vulnerability Description
There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard local user access. A local attacker can supply malicious strings that may be rendered and executed when a specific dialog within ArcGIS Pro is opened. This issue is fixed in ArcGIS Pro version 3.6.1.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Esri ArcGIS Pro 跨站脚本漏洞
Vulnerability Description
Esri ArcGIS Pro是美国Esri公司的一个地理信息系统软件。 Esri ArcGIS Pro 3.6.0及之前版本存在跨站脚本漏洞,该漏洞源于本地攻击者可注入恶意字符串,可能导致特定对话框打开时执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A