Unrated severityNVD Advisory· Published Dec 30, 2022· Updated Apr 10, 2025
Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
CVE-2022-38204
Description
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Affected products
1- Range: Portal for ArcGIS 10.7.1 and 10.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.