CVE-2025-57875: BUG-000164122 - Reflected XSS vulnerability in Portal for ArcGIS.
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57875?
CVE-2025-57875 is classified as a high-severity vulnerability due to the potential for remote attackers to execute arbitrary JavaScript code.
How do I fix CVE-2025-57875?
To remediate CVE-2025-57875, update to a patched version of Esri Portal for ArcGIS beyond 11.4.
Who is affected by CVE-2025-57875?
CVE-2025-57875 affects instances of Esri Portal for ArcGIS version 11.4 and below that have administrative access.
What type of vulnerability is CVE-2025-57875?
CVE-2025-57875 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2025-57875 be exploited remotely?
Yes, CVE-2025-57875 can be exploited remotely by authenticated users with administrative privileges.