CVE-2021-29116

MEDIUM

Esri ArcGIS Server 10.8.1 and 10.9 - Unauthenticated Stored Cross-Site Scripting via Feature Service Queries

Title source: llm
STIX 2.1

Description

A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.

Scores

CVSS v3 6.1
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
esri/arcgis_server 10.8.1
esri/arcgis_server 10.9.0
Published Dec 07, 2021
Tracked Since Feb 18, 2026