CVE-2025-67712: HTML injection issue in ArcGIS Web App Builder
There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67712?
The severity of CVE-2025-67712 is classified as a moderate risk due to the potential for HTML injection.
How do I fix CVE-2025-67712?
To fix CVE-2025-67712, upgrade to Esri ArcGIS Web AppBuilder developer edition version 2.30 or later.
Who is affected by CVE-2025-67712?
CVE-2025-67712 affects users of Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30.
What can an attacker do with CVE-2025-67712?
An attacker can exploit CVE-2025-67712 to execute arbitrary HTML in a victim's browser through phishing techniques.
Is CVE-2025-67712 a remote attack vector?
Yes, CVE-2025-67712 allows a remote, unauthenticated attacker to exploit the vulnerability.