There is SQL injection vulnerability in Esri ArcGIS...
High severity
Unreviewed
Published
Jul 19, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 19, 2023
Published to the GitHub Advisory Database
Jul 19, 2023
Last updated
Apr 4, 2024
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
References