Unvalidated Redirect Vulnerability in Esri Portal for ArcGIS by Esri
CVE-2025-57872
6.1MEDIUM
What is CVE-2025-57872?
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS versions 11.4 and earlier. This security flaw can be exploited by a remote, unauthenticated attacker who crafts a malicious URL, directing users to an arbitrary website. This vulnerability heightens the risk of phishing attacks, making it easier for attackers to deceive users into providing sensitive information. To mitigate this risk, it is crucial for users to apply the latest security patches and remain vigilant against suspicious links.
Affected Version(s)
Portal for ArcGIS Windows 10.9.1 <= 11.4
