CVE-2025-67711: Reflected XSS vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67711?
CVE-2025-67711 is classified as a high severity vulnerability due to its potential to allow remote unauthenticated attackers to execute malicious code.
How do I fix CVE-2025-67711?
To fix CVE-2025-67711, you should apply the latest security patches provided by Esri for ArcGIS Server versions prior to 11.5.
What are the risks associated with CVE-2025-67711?
The risks associated with CVE-2025-67711 include exposure to stored cross-site scripting attacks, which can lead to data theft or unauthorized actions performed in a user's browser.
What versions of Esri ArcGIS Server are affected by CVE-2025-67711?
CVE-2025-67711 affects Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux systems.
Who can be affected by CVE-2025-67711?
Any users accessing an affected version of Esri ArcGIS Server may be compromised if an attacker exploits this vulnerability to execute malicious scripts in their browsers.