CVE-2025-57871: BUG-000174020 - Reflected XSS vulnerability identified in Portal for ArcGIS. (11.3, 11.1, 10.9.1)
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57871?
CVE-2025-57871 is categorized as a critical reflected cross site scripting vulnerability.
How do I fix CVE-2025-57871?
To remediate CVE-2025-57871, it is recommended to apply the latest security patch provided by Esri for Portal for ArcGIS.
Who is affected by CVE-2025-57871?
CVE-2025-57871 affects users of Esri Portal for ArcGIS version 11.4 and below.
What impact does CVE-2025-57871 have on systems?
CVE-2025-57871 may allow a remote authenticated attacker to execute arbitrary JavaScript code in the browser.
Is CVE-2025-57871 a local or remote vulnerability?
CVE-2025-57871 is a remote vulnerability requiring authenticated administrative access to exploit.