CVE-2025-67703 | Esri ArcGIS Server up to 11.4 on Windows/Linux Configuration cross site scripting (EUVD-2025-206104 / WID-SEC-2025-2833)
A vulnerability was found in Esri ArcGIS Server up to 11.4 on Windows/Linux. It has been declared as problematic. This issue affects some unknown processing of the component Configuration Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-67703. It is possible to launch the attack remotely. No exploit is available.