CVE-2024-8149 MEDIUM

CVE-2024-8149: BUG-000168624 - Unvalidated redirect in Portal for ArcGIS.

Vendor Esri
Product Portal for ArcGIS
Weakness CWE-79 · XSS
Published October 4, 2024
Last update February 6, 2026

CVSS base score

4.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

There is a reflected Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may allow a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. Exploitation is limited to the same browser execution context and does not result in a change of security scope beyond the affected user session.

Key dates

02Disclosure timeline

October 4, 2024 CVE published
February 6, 2026 Record updated