Unvalidated Redirect Vulnerability in Esri Portal for ArcGIS by Esri
CVE-2025-57872
What is CVE-2025-57872?
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS versions 11.4 and earlier. This security flaw can be exploited by a remote, unauthenticated attacker who crafts a malicious URL, directing users to an arbitrary website. This vulnerability heightens the risk of phishing attacks, making it easier for attackers to deceive users into providing sensitive information. To mitigate this risk, it is crucial for users to apply the latest security patches and remain vigilant against suspicious links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Portal for ArcGIS Windows 10.9.1 <= 11.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
