CVE-2024-38036: BUG-000154827 - Reflected XSS in ArcGIS Experience Builder

5.4 CVSS

Description

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

Classification

CVE ID: CVE-2024-38036

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.4

Affected Products

Vendor: Esri

Product: Portal for ArcGIS Enterprise Experience Builder

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 16.18% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2024-update-2-released/

Timeline