Stored Cross-Site Scripting Vulnerability in Esri ArcGIS Server
CVE-2025-67705
What is CVE-2025-67705?
A stored cross-site scripting (XSS) vulnerability exists in Esri ArcGIS Server, affecting version 11.4 and earlier on both Windows and Linux platforms. This vulnerability allows a remote unauthenticated attacker to store malicious code, which could be executed within the context of a victim's browser. In certain configurations, this could lead to unauthorized actions and potential data exposure, posing significant risks to users and organizations relying on the affected software for critical mapping and geographical information services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ArcGIS Server Windows 10.9.1 <= 11.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
