Executive brief
ArcGIS Server is Esri's enterprise mapping and geospatial analysis platform used by organizations worldwide. A stored cross-site scripting vulnerability allows unauthenticated attackers to inject malicious code into the server that executes in users' browsers, potentially stealing credentials, session tokens, or sensitive geospatial data. The vulnerability affects versions 11.4 and earlier on both Windows and Linux deployments.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier. The vulnerability allows an unauthenticated remote attacker to store files containing malicious code that execute in the browser context of victims accessing affected ArcGIS Server instances. The attack requires no user authentication to inject the payload, though execution depends on the victim browsing to a URL that triggers the stored script. The vulnerability affects both Windows and Linux deployments under unspecified configurations. Patches are expected to be available through Esri's security update channels.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed