Описание
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.0 (включая)
cpe:2.3:a:tileserver:tileservergl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.19227
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 95%
0.19227
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79