CVE-2025-67708: Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67708?
CVE-2025-67708 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-67708?
To fix CVE-2025-67708, apply the latest security patches provided by Esri for ArcGIS Server.
What versions are affected by CVE-2025-67708?
CVE-2025-67708 affects Esri ArcGIS Server version 11.4 and earlier on both Windows and Linux.
Can CVE-2025-67708 be exploited remotely?
Yes, CVE-2025-67708 can be exploited by a remote unauthenticated attacker under certain configurations.
What type of vulnerability is CVE-2025-67708?
CVE-2025-67708 is a stored cross-site scripting (XSS) vulnerability that allows injection of malicious code.