{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2024-25706",
        "ASSIGNER": "psirt@esri.com",
        "STATE": "REJECT"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "** REJECT ** There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks."
            }
        ]
    }
}