Junglewise Threat Intelligence

CVE-2025-67704: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67704 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

ArcGIS Server is Esri's enterprise mapping and geospatial analysis platform used by organizations worldwide. A stored cross-site scripting vulnerability allows unauthenticated attackers to inject malicious code into the server that executes in users' browsers, potentially stealing credentials, session tokens, or sensitive geospatial data. The vulnerability affects versions 11.4 and earlier on both Windows and Linux deployments.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier. The vulnerability allows an unauthenticated remote attacker to store files containing malicious code that execute in the browser context of victims accessing affected ArcGIS Server instances. The attack requires no user authentication to inject the payload, though execution depends on the victim browsing to a URL that triggers the stored script. The vulnerability affects both Windows and Linux deployments under unspecified configurations. Patches are expected to be available through Esri's security update channels.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats