Esri ArcGIS Server
cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*
- <= 11.3
A stored cross-site scripting vulnerability has been identified in Esri ArcGIS Server versions through 11.3. This vulnerability allows remote, authenticated attackers with publisher capabilities to create a crafted link that, when clicked, could execute arbitrary JavaScript in the victim's browser. The vulnerability has a low impact on confidentiality and integrity, with no effect on availability.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users are advised to apply the ArcGIS Server Security 2025 Update 1 Patch, available through the Esri Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.