MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-29T00:00:00.000Z
Updated: 2025-07-29T17:34:31.951Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-44136

Updated: 2025-07-29T17:33:58.432Z

Status : Awaiting Analysis
Published: 2025-07-29T17:15:33.327
Modified: 2025-07-31T18:42:56.503
Link: CVE-2025-44136

No data.