CVE-2024-51946
Esri
CVE-2024-51946 is a stored Cross-Site Scripting (XSS) vulnerability found in ArcGIS Server versions 11.3 and earlier. This security flaw allows an authenticated attacker, with high privileges (publisher capabilities), to inject malicious JavaScript code into the application. When a user clicks on this crafted link, the injected code can execute in their browser.
While the CVSS score is 4.8, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk compared to critical vulnerabilities. However, the presence of CWE-79 highlights that XSS vulnerabilities can be exploited to steal sensitive information, modify website content, or perform actions on behalf of the user. This vulnerability could be exploited if an attacker gains the necessary privileges, potentially compromising confidentiality and integrity, although availability remains unaffected. Users of ArcGIS Server versions 11.3 and below should apply the necessary patches or upgrades to mitigate this risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.