Executive brief
Esri ArcGIS Server is a widely-deployed geospatial data and mapping platform used by organizations to publish and share geographic information. A stored cross-site scripting (XSS) vulnerability allows remote attackers without authentication to upload files containing malicious code that executes in the browsers of users viewing the affected content, potentially leading to session hijacking, credential theft, or other client-side attacks.
Technical details
A stored cross-site scripting vulnerability exists in ArcGIS Server version 11.4 and earlier on Windows and Linux platforms. The vulnerability permits remote, unauthenticated attackers to store files containing malicious code; when those files are accessed by victims through a web browser, the injected script executes in the user's browser context. The root cause appears to involve inadequate input validation or output encoding on user-supplied file content. Exploitation requires no authentication and is accessible over the network, though certain configuration states may be prerequisites. Patches are expected to be available; check Esri's security advisories for patched versions.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed