Junglewise Threat Intelligence

CVE-2025-67703: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67703 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

Esri ArcGIS Server is a mapping and geospatial data platform used by organizations to publish and manage geographic information. A vulnerability allows unauthenticated attackers to store malicious code that executes in users' browsers when they access the server, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Esri ArcGIS Server 11.4 and earlier on Windows and Linux platforms. The vulnerability allows remote unauthenticated attackers to upload or store files containing malicious JavaScript code that persists on the server. When victims access affected areas of the application, the injected code executes in their browser context with their privileges. The issue affects certain server configurations and requires no user authentication to exploit. A patch has been made available as part of the ArcGIS Server 2025 Update 2 security patch.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats