Executive brief
Esri ArcGIS Server, a geospatial data and mapping platform used by organizations worldwide, contains a stored cross-site scripting vulnerability in versions 11.4 and earlier. An unauthenticated attacker can upload malicious files that, when accessed by other users, execute code in their browsers. This could lead to credential theft, session hijacking, or unauthorized actions performed on behalf of affected users.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier on Windows and Linux platforms. The vulnerability allows a remote unauthenticated attacker to upload or store files containing malicious code that persists on the server. When other users access these files through their browsers, the malicious code executes in the context of the victim's session. The vulnerability appears to be configuration-dependent, meaning certain server setups are more susceptible. Patch availability and detailed remediation steps should be obtained from Esri's official security advisories.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed