An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.
References
Configurations
Information
Published : 2022-11-15 13:15
Updated : 2022-11-21 09:02
NVD link : CVE-2022-38201
Mitre link : CVE-2022-38201
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
esri
- arcgis_quickcapture