Stored Cross-Site Scripting Vulnerability in ArcGIS HUB and ArcGIS Enterprise Sites
CVE-2025-55104
4.8MEDIUM
What is CVE-2025-55104?
A stored cross-site scripting (XSS) vulnerability exists in ArcGIS HUB and ArcGIS Enterprise Sites, allowing an authenticated user with site creation or editing privileges to insert and store malicious XSS payloads. When triggered, these payloads can execute arbitrary JavaScript in the browsers of unsuspecting users, potentially leading to data theft, user impersonation, or further attacks on the affected web applications. Organizations using these Esri products should ensure their user roles are appropriately managed and implement safety measures to mitigate potential exploitation.
Affected Version(s)
Portal for ArcGIS Enterprise Sites Windows 10.9.1 <= 11.4
