Логотип exploitDog
bind:CVE-2025-44136
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-44136

Количество 2

Количество 2

nvd логотип

CVE-2025-44136

6 месяцев назад

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-cj86-6g7w-75f6

6 месяцев назад

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-44136

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

CVSS3: 9.8
10%
Средний
6 месяцев назад
github логотип
GHSA-cj86-6g7w-75f6

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

CVSS3: 9.8
10%
Средний
6 месяцев назад

Уязвимостей на страницу