CNNVD-202509-4366 Information

CNNVD ID

CNNVD-202509-4366

CVE-2025-57879

  • CNNVD Published: 2025-09-29

Description (Chinese)

Esri Portal For ArcGIS是Esri公司的一种允许在组织内与其他人共享地图、场景、应用程序和其他地理信息的组件。 Esri Portal for ArcGIS 11.4及之前版本存在输入验证错误漏洞,该漏洞源于未验证的重定向,可能导致远程未经验证的攻击者制作URL将受害者重定向到任意网站,简化钓鱼攻击。

Description (English)

Esri Portal For ArcGIS is a component of Esri that allows for the sharing of maps, scenes, applications and other geographic information within the organization. Esri Portal for ArcGIS 11.4 and earlier versions had input validation bugs, which stemmed from unverified re-direction, which could lead to remote unverified attackers producing URLs that redirected victims to random websites and simplified fishing attacks.

Hazard Level

High

Vulnerability Type

输入验证错误

Affected Vendor

环境系统研究所

Published

2025-09-29

Last Modified

2026-02-24

References

https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch https://vigilance.fr/vulnerability/Portal-for-ArcGIS-multiple-vulnerabilities-dated-16-09-2025-48236

Patch

https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch

Share on: