CVE-2022-38198
25.10.2022, 17:15
There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victims browser.
Vendor | Product | Version |
---|---|---|
esri | arcgis_server | 𝑥 ≤ 10.9.1 |
𝑥
= Vulnerable software versions