Medium severity6.1NVD Advisory· Published Oct 1, 2021· Updated Jun 17, 2026
CVE-2021-29109
CVE-2021-29109
Description
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
Affected products
3<=10.9+ 2 more
- (no CPE)range: <=10.9
- (no CPE)range: All
- cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*range: <=10.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.