CVE-2025-57873: BUG-000175222 - Reflected XSS vulnerability in Portal for ArcGIS.
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57873?
CVE-2025-57873 is classified as a reflected cross-site scripting vulnerability that poses a risk to users of Esri Portal for ArcGIS 11.4 and below.
How do I fix CVE-2025-57873?
To mitigate CVE-2025-57873, users should update Esri Portal for ArcGIS to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-57873?
CVE-2025-57873 affects users of Esri Portal for ArcGIS version 11.4 and below, particularly those with administrative access.
What type of attack is possible with CVE-2025-57873?
CVE-2025-57873 allows a remote authenticated attacker to execute arbitrary JavaScript code in the browser through crafted input.
What should I do if I can't update from an affected version for CVE-2025-57873?
If unable to update from an affected version, consider implementing additional security measures such as input validation and sanitization to mitigate CVE-2025-57873 risks.