CVE-2024-38037

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:esri:portal_for_arcgis:10.9.1:*:*:*:*:*:*:*
cpe:2.3:a:esri:portal_for_arcgis:11.0:*:*:*:*:*:*:*

History

10 Apr 2025, 19:16

Type Values Removed Values Added
Summary (en) There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and 10.9.1 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. (en) There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Information

Published : 2024-10-04 18:15

Updated : 2025-04-10 19:16


NVD link : CVE-2024-38037

Mitre link : CVE-2024-38037

CVE.ORG link : CVE-2024-38037


JSON object : View

Products Affected

esri

  • portal_for_arcgis
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')