PT-2025-31223 · Maptiler · Maptiler Tileserver-Php

Mheranco

·

Published

2025-07-29

·

Updated

2025-11-07

·

CVE-2025-44136

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MapTiler Tileserver-php version 2.0
Description MapTiler Tileserver-php v2.0 is susceptible to a Cross-Site Scripting (XSS) issue. The layer GET parameter is reflected in an error message without proper HTML encoding. This allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code in a victim's browser via the ''/api/v1/layer'' endpoint. The vulnerable parameter is layer.
Recommendations MapTiler Tileserver-php version 2.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-44136

Affected Products

Maptiler Tileserver-Php