Stored Cross-Site Scripting Vulnerability in Esri Portal for ArcGIS Enterprise
CVE-2025-55103
What is CVE-2025-55103?
A stored Cross-Site Scripting vulnerability exists in Esri Portal for ArcGIS Enterprise versions 10.9.1 through 11.4. This flaw allows an authenticated remote attacker to upload files containing malicious scripts. When executed, these scripts can run arbitrary JavaScript code within the user's browser, potentially exposing sensitive information such as privileged tokens. Such exposure could enable the attacker to gain unauthorized control over the Portal, significantly compromising the security of the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Portal for ArcGIS Enterprise Sites Windows 10.9.1 <= 11.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
