Executive brief
Esri ArcGIS Server is a mapping and spatial analysis platform used by organizations to create and share geographic data and applications. A stored cross-site scripting vulnerability allows unauthenticated attackers to inject malicious code into the server, which then executes when legitimate users access affected content in their browsers, potentially compromising user sessions, stealing credentials, or hijacking administrator accounts.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms. An unauthenticated remote attacker can store files containing malicious JavaScript code on the server through an unspecified vector. In certain configurations, this stored malicious code executes in the browser context of victims who access the affected content, potentially allowing session hijacking, credential theft, or further compromise. The flaw requires specific server configurations to be exploitable and affects the Windows and Linux distributions of the product.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed