Loading HuntDB...

GHSA-rj8v-47w4-c66w

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

Related CVEs

Key Information

GHSA ID
GHSA-rj8v-47w4-c66w
Published
April 4, 2024 6:30 PM
Last Modified
April 10, 2025 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.