Stored Cross-Site Scripting Vulnerability in ArcGIS HUB and ArcGIS Enterprise Sites
CVE-2025-55104

4.8MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
21 August 2025

What is CVE-2025-55104?

A stored cross-site scripting (XSS) vulnerability exists in ArcGIS HUB and ArcGIS Enterprise Sites, allowing an authenticated user with site creation or editing privileges to insert and store malicious XSS payloads. When triggered, these payloads can execute arbitrary JavaScript in the browsers of unsuspecting users, potentially leading to data theft, user impersonation, or further attacks on the affected web applications. Organizations using these Esri products should ensure their user roles are appropriately managed and implement safety measures to mitigate potential exploitation.

Affected Version(s)

Portal for ArcGIS Enterprise Sites Windows 10.9.1 <= 11.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.