CVE-2025-57874: BUG-000161627 - Reflected XSS vulnerability in Portal for ArcGIS. (11.3, 11.1, 10.9.1)
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57874?
CVE-2025-57874 is classified as a reflected cross site scripting vulnerability which can potentially allow arbitrary JavaScript execution.
How do I fix CVE-2025-57874?
To mitigate CVE-2025-57874, upgrade your Esri Portal for ArcGIS to version 11.5 or apply the recommended security patches.
Who is affected by CVE-2025-57874?
CVE-2025-57874 affects users of Esri Portal for ArcGIS versions 11.4 and below, especially those with administrative access.
What type of attack can CVE-2025-57874 enable?
CVE-2025-57874 can enable a remote authenticated attacker to execute arbitrary JavaScript code in the victim's browser.
Is CVE-2025-57874 a local or remote vulnerability?
CVE-2025-57874 is a remote vulnerability that requires an attacker to be authenticated with administrative access.