Junglewise Threat Intelligence

CVE-2025-67705: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67705 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

Esri ArcGIS Server is a widely-deployed geospatial data and mapping platform used by organizations to publish and share geographic information. A stored cross-site scripting (XSS) vulnerability allows remote attackers without authentication to upload files containing malicious code that executes in the browsers of users viewing the affected content, potentially leading to session hijacking, credential theft, or other client-side attacks.

Technical details

A stored cross-site scripting vulnerability exists in ArcGIS Server version 11.4 and earlier on Windows and Linux platforms. The vulnerability permits remote, unauthenticated attackers to store files containing malicious code; when those files are accessed by victims through a web browser, the injected script executes in the user's browser context. The root cause appears to involve inadequate input validation or output encoding on user-supplied file content. Exploitation requires no authentication and is accessible over the network, though certain configuration states may be prerequisites. Patches are expected to be available; check Esri's security advisories for patched versions.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats