CVE-2024-25705: Esri Portal For Arcgis

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s browser. Exploitation requires basic authenticated access but does not require elevated or administrative privileges, indicating low privileges are required.

Affected products

  • Esri Portal For Arcgis: up to and including 11.1

Published 2024-04-04. Last modified 2026-06-17.