CNNVD-202509-4368 Information
CNNVD ID
CNNVD-202509-4368
Related CVE
- CNNVD Published: 2025-09-29
Description (Chinese)
Esri Portal For ArcGIS是Esri公司的一种允许在组织内与其他人共享地图、场景、应用程序和其他地理信息的组件。 Esri Portal for ArcGIS 11.4及之前版本存在输入验证错误漏洞,该漏洞源于存在未经验证的重定向,可能导致远程未经验证攻击者制作URL将受害者重定向到任意网站,简化钓鱼攻击。
Description (English)
Esri Portal For ArcGIS is a component of Esri that allows for the sharing of maps, scenes, applications and other geographic information within the organization. Esri Portal for ArcGIS 11.4 and earlier versions had input-validation errors, which stemmed from unverified re-direction, which could lead to remote unverified attackors producing URLs to redirect victims back to random websites and to simplify fishing attacks.
Hazard Level
High
Vulnerability Type
输入验证错误
Affected Vendor
环境系统研究所
Published
2025-09-29
Last Modified
2026-02-24
References
https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch https://vigilance.fr/vulnerability/Portal-for-ArcGIS-multiple-vulnerabilities-dated-16-09-2025-48236