Junglewise Threat Intelligence

CVE-2025-67708: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67708 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

Esri ArcGIS Server is a geospatial data and mapping platform used by organizations to publish and manage geographic information. A flaw allows attackers without authentication to upload files containing malicious scripts that execute in users' browsers, potentially compromising data or stealing credentials when victims access affected server resources.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier on Windows and Linux platforms. The vulnerability exists in a component that accepts file uploads without sufficient input validation or output encoding, allowing an unauthenticated remote attacker to store malicious JavaScript that executes in the browser context of subsequent users who access the affected content. The attack requires no user interaction beyond normal browsing behavior. The vulnerability affects certain server configurations that expose the vulnerable upload or storage mechanism to unauthenticated access.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats