peter bassill · operator
$ cve CVE-2020-15500 JSON

CVE-2020-15500 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 12.2% (pctl 96)

Patch early

A public exploit exists.

Description

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS12.22% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2020-07-01
Last modified2026-06-17

Affected (1)

VendorProduct
tileservertileservergl

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD