Junglewise Threat Intelligence

CVE-2025-67710: Esri ArcGIS Server stored cross-site scripting

CVE-2025-67710 · Severity: medium · CVSS 6.1 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

Esri ArcGIS Server, a geospatial data and mapping platform used by organizations worldwide, contains a stored cross-site scripting vulnerability in versions 11.4 and earlier. An unauthenticated attacker can upload malicious files that, when accessed by other users, execute code in their browsers. This could lead to credential theft, session hijacking, or unauthorized actions performed on behalf of affected users.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier on Windows and Linux platforms. The vulnerability allows a remote unauthenticated attacker to upload or store files containing malicious code that persists on the server. When other users access these files through their browsers, the malicious code executes in the context of the victim's session. The vulnerability appears to be configuration-dependent, meaning certain server setups are more susceptible. Patch availability and detailed remediation steps should be obtained from Esri's official security advisories.

Affected products

  • Esri ArcGIS Server 11.4 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats