TileServer API - Cross Site Scripting
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.
Tileserver GLPoC 已收录
CVSS6.1EPSS 4.6%
Tileserver GL是一个开源项目,旨在实现一个轻量级且功能齐全的瓦片服务。它可以在任何地方运行,包括本地计算机、云平台和边缘设备。Tileserver GL支持多种数据格式,包括GeoJSON、MVT和瓦片。它还支持多种地图渲染引擎,包括Mapbox GL JS和Leaflet。
共找到 2 条公开漏洞记录
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.
TileServer GL through 3.0.0 is vulnerable to reflected cross-site scripting via server.js because the content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page.