Stored Cross-site Scripting Vulnerability in Esri Portal for ArcGIS
CVE-2025-57876

4.8MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
29 September 2025

What is CVE-2025-57876?

A stored Cross-site Scripting vulnerability exists in Esri's Portal for ArcGIS, specifically affecting version 11.4 and earlier. This issue allows a remote, authenticated attacker to inject malicious scripts into stored content, potentially executing arbitrary JavaScript code in the browsers of users who access the compromised content. The elevated privileges required for this attack mean that sensitive token information can be disclosed, granting attackers significant control over the affected Portal environment. It's essential for organizations using this product to apply the latest security patch and mitigate the risk of exploitation.

Affected Version(s)

Portal for ArcGIS Windows 10.9.1 <= 11.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.