← Back

CVE-2025-44136

Published: Jul 29, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

Affected (1)

1 product
Tileserver Php
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0

References (2)

Source: cve@mitre.org
ExploitIssue Tracking
Source: cve@mitre.org
Exploit

Timeline

No history available yet.