Executive brief
Esri ArcGIS Server is a mapping and geographic information system platform used by enterprises to manage geospatial data and services. An attacker can store malicious code on the server, which executes in victims' browsers when they view the affected content, potentially leading to account compromise, data theft, or session hijacking without requiring authentication.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in ArcGIS Server 11.4 and earlier on Windows and Linux. The vulnerability allows a remote unauthenticated attacker to store files containing malicious JavaScript code through certain configuration endpoints. When an authenticated user accesses the stored content, the script executes in their browser context with their privileges, potentially granting the attacker access to sensitive data or administrative functions. The vulnerability affects specific configurations; not all deployments are equally exposed. A patch is expected to be available from Esri.
Affected products
- Esri ArcGIS Server 11.4 and earlier
Timeline
- 2025-12-31: disclosed