CVE-2025-57877: Reflected XSS vulnerability in Portal for ArcGIS.
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57877?
CVE-2025-57877 is considered a high severity vulnerability due to its potential for arbitrary code execution in the browser.
How do I fix CVE-2025-57877?
To fix CVE-2025-57877, update Esri Portal for ArcGIS to version 11.5 or later where the vulnerability has been patched.
Who is affected by CVE-2025-57877?
CVE-2025-57877 affects users of Esri Portal for ArcGIS versions 11.4 and below.
What types of attacks are possible with CVE-2025-57877?
CVE-2025-57877 allows remote authenticated attackers to execute arbitrary JavaScript code in victim browsers.
Is authentication required to exploit CVE-2025-57877?
Yes, CVE-2025-57877 requires the attacker to have administrative access to exploit the vulnerability.