Security Advisory

CVE-2025-67712

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-19 20:05:42
Last updated 2026-01-08 16:47:34
Assigner Esri
State PUBLISHED

Description

There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victims browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.