CVE-2023-25838

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 19, 2023
Updated: May 21, 2024
CWE ID 89

Summary

CVE-2023-25838 is a newly discovered SQL injection vulnerability affecting Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise. This issue enables remote, authorized attackers to execute arbitrary SQL commands against the back-end database. The exploitation of this vulnerability requires considerable effort and expertise, making successful attacks unlikely but still a potential threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share