CVE-2024-8148

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 10.8.1 - 11.2 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Configurations

No configuration.

History

07 Oct 2024, 17:48

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de redirección no validada en Esri Portal for ArcGIS 10.8.1 - 11.2 que puede permitir que un atacante remoto no autenticado cree una URL que podría redirigir a una víctima a un sitio web arbitrario, simplificando los ataques de phishing.

04 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 18:15

Updated : 2024-10-07 17:48


NVD link : CVE-2024-8148

Mitre link : CVE-2024-8148

CVE.ORG link : CVE-2024-8148


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')