CVE-2025-67711
MED 6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Applications in Environment
3
ArcGIS Pro
v3.6.0.59527
9 devices
ArcGIS Pro
v3.0.0.36056
1 device
server
v1.0.0.0
1 device