A vulnerability labeled as problematic has been found in Esri ArcGIS Server up to 11.4 on Windows/Linux. This affects an unknown function of the component Configuration Handler. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2025-67709. The attack may be launched remotely. There is no exploit available.