CVE-2025-57872: BUG-000174150 - Unvalidated redirect in Portal for ArcGIS.
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57872?
CVE-2025-57872 is considered a moderate severity vulnerability that could facilitate phishing attacks due to unvalidated redirects in Esri Portal for ArcGIS.
How do I fix CVE-2025-57872?
To remediate CVE-2025-57872, update Esri Portal for ArcGIS to version 11.4 or newer, which includes patches addressing this vulnerability.
Who is affected by CVE-2025-57872?
CVE-2025-57872 affects all users of Esri Portal for ArcGIS version 11.4 and below.
What type of vulnerability is CVE-2025-57872?
CVE-2025-57872 is an unvalidated redirect vulnerability that can be exploited by remote, unauthenticated attackers.
What could an attacker achieve by exploiting CVE-2025-57872?
An attacker exploiting CVE-2025-57872 could redirect victims to arbitrary websites, potentially leading to successful phishing attacks.