Medium severity5.4NVD Advisory· Published Apr 4, 2024· Updated Jun 17, 2026
CVE-2024-25705
CVE-2024-25705
Description
There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. Exploitation requires basic authenticated access but does not require elevated or administrative privileges, indicating low privileges are required.
Affected products
3cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*range: <=11.1
- (no CPE)range: all
- Range: <=11.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.