CVE-2025-55107

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/08/2025
Last modified:
05/09/2025

Description

There is a stored<br /> Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites<br /> versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to<br /> inject malicious a file with an embedded xss script which when loaded could<br /> potentially execute arbitrary JavaScript code in the victim’s browser. The<br /> privileges required to execute this attack are high. The attack could<br /> disclose a privileged token which may result in the attacker gaining full<br /> control of the Portal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* 10.9.1 (including) 11.4 (including)