CVE-2024-25692: Esri Portal For Arcgis

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.

Affected products

  • Esri Portal For Arcgis: up to and including 11.1

Published 2024-04-04. Last modified 2026-06-17.