CVE-2023-25840: Esri Arcgis Server

Low severity, CVSS 3.4. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.

Affected products

  • Esri Arcgis Server: from 10.8.1, before 11.1 (fixed in 11.1)

Published 2023-07-21. Last modified 2026-06-17.