Junglewise Threat Intelligence

CVE-2025-67709: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67709 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

Esri ArcGIS Server is a mapping and spatial analysis platform used by organizations to create and share geographic data and applications. A stored cross-site scripting vulnerability allows unauthenticated attackers to inject malicious code into the server, which then executes when legitimate users access affected content in their browsers, potentially compromising user sessions, stealing credentials, or hijacking administrator accounts.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms. An unauthenticated remote attacker can store files containing malicious JavaScript code on the server through an unspecified vector. In certain configurations, this stored malicious code executes in the browser context of victims who access the affected content, potentially allowing session hijacking, credential theft, or further compromise. The flaw requires specific server configurations to be exploitable and affects the Windows and Linux distributions of the product.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats