CNNVD-202509-4368 Information

CNNVD ID

CNNVD-202509-4368

CVE-2025-57878

  • CNNVD Published: 2025-09-29

Description (Chinese)

Esri Portal For ArcGIS是Esri公司的一种允许在组织内与其他人共享地图、场景、应用程序和其他地理信息的组件。 Esri Portal for ArcGIS 11.4及之前版本存在输入验证错误漏洞,该漏洞源于存在未经验证的重定向,可能导致远程未经验证攻击者制作URL将受害者重定向到任意网站,简化钓鱼攻击。

Description (English)

Esri Portal For ArcGIS is a component of Esri that allows for the sharing of maps, scenes, applications and other geographic information within the organization. Esri Portal for ArcGIS 11.4 and earlier versions had input-validation errors, which stemmed from unverified re-direction, which could lead to remote unverified attackors producing URLs to redirect victims back to random websites and to simplify fishing attacks.

Hazard Level

High

Vulnerability Type

输入验证错误

Affected Vendor

环境系统研究所

Published

2025-09-29

Last Modified

2026-02-24

References

https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch https://vigilance.fr/vulnerability/Portal-for-ArcGIS-multiple-vulnerabilities-dated-16-09-2025-48236

Patch

https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-3-patch

Share on: