A vulnerability, which was classified as problematic, was found in Esri Portal for ArcGIS up to 10.8.1/10.9.1/11.1. This affects an unknown part of the component Link Handler. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2024-38038. It is possible to initiate the attack remotely. There is no exploit available.