PoC Index

CVE-2020-15500

MEDIUM 6.1EPSS 12.2%

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
12.22% chance of exploitation in the next 30 days, 96th percentile
Nuclei
medium · CWE-79
Published
2020-07-01
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related