Stored Cross-Site Scripting Vulnerability in Esri Portal for ArcGIS Enterprise
CVE-2025-55103
4.8MEDIUM
What is CVE-2025-55103?
A stored Cross-Site Scripting vulnerability exists in Esri Portal for ArcGIS Enterprise versions 10.9.1 through 11.4. This flaw allows an authenticated remote attacker to upload files containing malicious scripts. When executed, these scripts can run arbitrary JavaScript code within the user's browser, potentially exposing sensitive information such as privileged tokens. Such exposure could enable the attacker to gain unauthorized control over the Portal, significantly compromising the security of the affected systems.
Affected Version(s)
Portal for ArcGIS Enterprise Sites Windows 10.9.1 <= 11.4
