CVE-2023-25841: Esri Arcgis Server

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Mitigation: Disable anonymous access to ArcGIS Feature services with edit capabilities.

Affected products

  • Esri Arcgis Server: from 10.8.1, before 11.1 (fixed in 11.1)

Published 2023-07-21. Last modified 2026-06-17.