CVE-2025-57876: Stored XSS vulnerability in Portal for ArcGIS
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57876?
CVE-2025-57876 is considered a high-severity vulnerability due to its potential for remote code execution through stored Cross-site Scripting.
How do I fix CVE-2025-57876?
To fix CVE-2025-57876, upgrade Esri Portal for ArcGIS to version 11.5 or later, where the vulnerability has been patched.
Who is affected by CVE-2025-57876?
CVE-2025-57876 affects all versions of Esri Portal for ArcGIS up to and including version 11.4.
What kind of attack can be executed through CVE-2025-57876?
CVE-2025-57876 can allow an authenticated attacker to inject a malicious script that executes arbitrary JavaScript code in a victim's browser.
Is user authentication required to exploit CVE-2025-57876?
Yes, CVE-2025-57876 requires user authentication, which means only authenticated users can exploit this vulnerability.