CVE-2025-67705: Reflected XSS vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67705?
CVE-2025-67705 is considered a high severity vulnerability due to the potential for remote code execution in affected systems.
How do I fix CVE-2025-67705?
To fix CVE-2025-67705, update your Esri ArcGIS Server to version 11.5 or later, where the vulnerability has been addressed.
Which versions of Esri ArcGIS Server are affected by CVE-2025-67705?
CVE-2025-67705 affects Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms.
What type of vulnerability is CVE-2025-67705?
CVE-2025-67705 is categorized as a stored cross-site scripting (XSS) vulnerability that can be exploited to execute malicious code.
Can CVE-2025-67705 be exploited remotely?
Yes, CVE-2025-67705 can be exploited remotely by unauthenticated attackers under certain configurations.