Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-44137

Опубликовано: 29 июл. 2025
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web server. Affected GET parameters are "TileMatrix", "TileRow", "TileCol" and "Format"

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:maptiler:tileserver_php:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00459
Низкий

8.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.2
github
6 месяцев назад

MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web server. Affected GET parameters are "TileMatrix", "TileRow", "TileCol" and "Format"

EPSS

Процентиль: 64%
0.00459
Низкий

8.2 High

CVSS3

Дефекты

CWE-22