Remote file inclusion vulnerability in ArcGIS Server help documentation
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.7epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw in ArcGIS Server's help documentation allows attackers to inject malicious HTML code into web pages without needing to log in. This could trick users into visiting compromised pages or stealing their information.
Technical detail
Remote file inclusion vulnerability in ArcGIS Server help documentation permits unauthenticated attackers to inject arbitrary HTML content via request manipulation. The attack vector is web-based and requires no authentication; successful exploitation results in HTML injection, enabling phishing, credential theft, or malware distribution to end users accessing the help section.
Summary generated and translated by AI from the official description.
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Affected products
Esri · ArcGIS Server