There is an unvalidated redirect vulnerability in Esri...
Moderate severity
Unreviewed
Published
Sep 29, 2025
to the GitHub Advisory Database
•
Updated Sep 29, 2025
Description
Published by the National Vulnerability Database
Sep 29, 2025
Published to the GitHub Advisory Database
Sep 29, 2025
Last updated
Sep 29, 2025
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
References