CVE-2025-55107 – Esri Portal for ArcGIS Enterprise Sites Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the
CVE-2025-55107 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 21, 2025

    Action Type Old Value New Value
    Added Description There is a stored
    Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites
    versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to
    inject malicious a file with an embedded xss script which when loaded could
    potentially execute arbitrary JavaScript code in the victim’s browser. The
    privileges required to execute this attack are high. The attack could
    disclose a privileged token which may result in the attacker gaining full
    control of the Portal.
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
    Added CWE CWE-79
    Added Reference https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/2925891-2
Share the Post:

Related Posts