Description


ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.

Weaknesses



CWE-434

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

5.6 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-12-31T23:15:41.687Z

2 weeks ago

Last modified

2026-01-06T19:08:47.110Z

1 week ago