CVE-2023-25841: Esri Arcgis Server
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Mitigation: Disable anonymous access to ArcGIS Feature services with edit capabilities.
Affected products
- Esri Arcgis Server: from 10.8.1, before 11.1 (fixed in 11.1)
Published 2023-07-21. Last modified 2026-06-17.