CVE-2023-25837

Publication date

2023-07-21 03:42:24

Family

Esri

State

PUBLISHED

Description

There is a Cross-site Scripting vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked by a victim could potentially execute arbitrary JavaScript code in the targets browser.  The privileges required to execute this attack are high.    The impact to Confidentiality, Integrity and Availability are High.