CVE-2020-15500 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 12.2% (pctl 96)
Patch early
A public exploit exists.
Description
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 12.22% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-07-01 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| tileserver | tileservergl |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS) | 2021-04-15 |
References
→ the Explorer · watch your stack · NVD