CVE-2025-1726
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 26, 2025
CWE ID 89
Summary
CVE-2025-1726 is a SQL injection vulnerability affecting Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux. An attacker with low privileges can exploit this flaw to read limited database schema information by crafting malicious queries. Although some internal database identifiers can be enumerated, the potential impact on confidentiality is rated as low due to encryption of any sensitive data returned. There is no evidence of impact on the integrity or availability vectors. This issue is resolved in ArcGIS Monitor 2024.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.