CNNVD-202509-4374 Information
CNNVD ID
CNNVD-202509-4374
Related CVE
- CNNVD Published: 2025-09-29
Description (Chinese)
Esri Portal For ArcGIS是Esri公司的一种允许在组织内与其他人共享地图、场景、应用程序和其他地理信息的组件。 Esri Portal for ArcGIS 11.4及之前版本存在输入验证错误漏洞,该漏洞源于未验证的重定向,可能导致远程未经验证的攻击者制作URL将受害者重定向到任意网站,简化钓鱼攻击。
Description (English)
Esri Portal For ArcGIS is a component of Esri that allows for the sharing of maps, scenes, applications and other geographic information within the organization. Esri Portal for ArcGIS 11.4 and earlier versions had input validation bugs, which stemmed from unverified re-direction, which could lead to remote unverified attackers producing URLs that redirected victims to random websites and simplified fishing attacks.
Hazard Level
High
Vulnerability Type
输入验证错误
Affected Vendor
环境系统研究所
Published
2025-09-29
Last Modified
2026-02-24
References
https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch https://vigilance.fr/vulnerability/Portal-for-ArcGIS-multiple-vulnerabilities-dated-16-09-2025-48236