PT-2025-38619 · Mapserver+1 · Mapserver+1
Alwin Warringa
·
Published
2025-09-18
·
Updated
2025-10-17
·
CVE-2025-59431
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MapServer versions prior to 8.4.1
Description
MapServer, a system for developing web-based GIS applications, contains a flaw in the XML Filter Query directive PropertyName. The PropertyName directive is susceptible to Boolean-based SQL injection due to bypassed expression checking when double quote characters are introduced. This allows manipulation of backend database queries.
Recommendations
Update to MapServer version 8.4.1 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Mapserver