CVE-2013-7231: Esri Arcgis Server

Low severity, CVSS 3.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.

Affected products

  • Esri Arcgis Server: version 10.1 only; version 10.2 only

Published 2013-12-30. Last modified 2026-06-17.