CVE-2025-67703: Stored XSS vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67703?
CVE-2025-67703 is considered a high severity vulnerability due to the potential for remote code execution via stored cross-site scripting.
How do I fix CVE-2025-67703?
To fix CVE-2025-67703, upgrade to Esri ArcGIS Server version 11.5 or later, where this vulnerability has been addressed.
What versions of Esri ArcGIS Server are affected by CVE-2025-67703?
CVE-2025-67703 affects Esri ArcGIS Server 11.4 and earlier versions.
What type of attack does CVE-2025-67703 facilitate?
CVE-2025-67703 facilitates stored cross-site scripting attacks that can execute malicious code in a victim's browser.
Who can exploit CVE-2025-67703?
CVE-2025-67703 can be exploited by remote unauthenticated attackers in certain configurations of the software.