VYPR

Arcgis Quickcapture

by Esri

CVEs (2)

  • CVE-2022-38209MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38201MedNov 15, 2022
    risk 0.40cvss 6.1epss 0.00

    An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.