CVE-2019-16193: Esri Arcgis Enterprise

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

Affected products

  • Esri Arcgis Enterprise: version 10.6.1 only

Published 2019-09-11. Last modified 2026-06-17.