CVE-2025-67708 | Esri ArcGIS Server up to 11.4 on Windows/Linux Configuration cross site scripting (EUVD-2025-206099 / WID-SEC-2025-2833)
A vulnerability identified as problematic has been detected in Esri ArcGIS Server up to 11.4 on Windows/Linux. The impacted element is an unknown function of the component Configuration Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-67708. The attack may be initiated remotely. There is no available exploit.