Medium severity6.1NVD Advisory· Published Nov 15, 2022· Updated Jun 17, 2026
CVE-2022-38201
CVE-2022-38201
Description
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.
Affected products
3cpe:2.3:a:esri:arcgis_quickcapture:*:*:*:*:*:*:x64:*+ 1 more
- cpe:2.3:a:esri:arcgis_quickcapture:*:*:*:*:*:*:x64:*range: >=10.8.1,<=10.9.1
- (no CPE)range: 10.8.1
- Range: 10.8.1 - 10.9.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.