CVE-2025-57878: BUG-000174149 - The Portal for ArcGIS has an unvalidated redirect.
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57878?
CVE-2025-57878 is classified as a moderate severity vulnerability due to its potential to facilitate phishing attacks.
How do I fix CVE-2025-57878?
To fix CVE-2025-57878, update your Esri Portal for ArcGIS to version 11.4 or later, where the vulnerability has been addressed.
What impact does CVE-2025-57878 have on users?
CVE-2025-57878 allows attackers to redirect users to malicious websites, increasing the risk of phishing attacks.
Which versions of Esri Portal for ArcGIS are affected by CVE-2025-57878?
CVE-2025-57878 affects Esri Portal for ArcGIS versions 11.4 and below.
Is CVE-2025-57878 an authenticated vulnerability?
No, CVE-2025-57878 is a remote, unauthenticated vulnerability that can be exploited without user credentials.