在 Esri Portal for ArcGIS 11.3 及更早版本中存在 HTML 注入漏洞,允许具有管理员权限的远程攻击者在管理 API 中插入任意 HTML 内容。建议正在使用 ArcGIS Enterprise 11.1 和 11.3 的用户进行补丁修复。建议所有用户升级至最新的长期支持(LTS)版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Esri | Portal for ArcGIS | 11.1≤ 11.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Esri | Portal for ArcGIS | 11.1 ~ 11.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69236 | 6.1 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69234 | 6.1 MEDIUM | reflected cross site scripting vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69235 | 6.1 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69224 | 5.9 MEDIUM | information disclosure vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69225 | 5.9 MEDIUM | information disclosure vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69230 | 5.5 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69231 | 5.5 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69232 | 5.5 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69233 | 5.5 MEDIUM | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69229 | 5.4 MEDIUM | HTML injection vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69228 | 5.3 MEDIUM | missing authentication vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69238 | 3.5 LOW | HTML injection vulnerability in Esri Portal for ArcGIS |
No comments yet