← Back to browse · API

CVE-2024-25693

Severity
CRITICAL
CVSS
9.9
EPSS
0.01265
Risk score
40.04
CISA KEV
No
PoC
No
Published
2024-04-04
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-23009, GHSA-85R2-29G6-F4W7
Products
Esri:Portal for ArcGIS, Esri:Portal for ArcGIS all ≤≤11.2
Sources
euvd EUVD-2024-23009

Description

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory.

References