CVE-2025-67709: There is a cross site scripting issue in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67709?
CVE-2025-67709 has a high severity due to its potential for remote code execution via stored cross site scripting.
How do I fix CVE-2025-67709?
To fix CVE-2025-67709, update to the latest version of Esri ArcGIS Server, specifically version 11.5 or later.
What systems are affected by CVE-2025-67709?
CVE-2025-67709 affects Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms.
Can CVE-2025-67709 be exploited remotely?
Yes, CVE-2025-67709 allows for remote exploitation by unauthenticated attackers in certain configurations.
What kind of attack does CVE-2025-67709 facilitate?
CVE-2025-67709 facilitates stored cross site scripting attacks that can execute malicious code in victims' browsers.