CVE-2020-15500
Summary
| CVE | CVE-2020-15500 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-01 23:15:00 UTC |
| Updated | 2022-11-10 04:25:00 UTC |
| Description | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Reflected XSS vulnerability in the application main page · Issue #461 · maptiler/tileserver-gl · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Tileserver-gl 3.0.0 Cross Site Scripting ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982585 Nodejs (npm) Security Update for tileserver-gl (GHSA-3fr8-mwpp-8h9p)