Executive brief
Esri ArcGIS Server is a geospatial data and mapping platform used by organizations to publish and manage geographic information. A flaw allows attackers without authentication to upload files containing malicious scripts that execute in users' browsers, potentially compromising data or stealing credentials when victims access affected server resources.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier on Windows and Linux platforms. The vulnerability exists in a component that accepts file uploads without sufficient input validation or output encoding, allowing an unauthenticated remote attacker to store malicious JavaScript that executes in the browser context of subsequent users who access the affected content. The attack requires no user interaction beyond normal browsing behavior. The vulnerability affects certain server configurations that expose the vulnerable upload or storage mechanism to unauthenticated access.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed