Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj86-6g7w-75f6

Опубликовано: 29 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

EPSS

Процентиль: 93%
0.10019
Средний

9.8 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

EPSS

Процентиль: 93%
0.10019
Средний

9.8 Critical

CVSS3

Дефекты

CWE-79