CVE-2022-38190

MEDIUM

Esri Portal for ArcGIS < 10.8.1 - Unauthenticated Stored Cross-Site Scripting via Configurable Apps

Title source: llm
STIX 2.1

Description

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser

Scores

CVSS v3 6.1
EPSS 0.0049
EPSS Percentile 65.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
esri/portal_for_arcgis < 10.8.1
Published Aug 15, 2022
Tracked Since Feb 18, 2026