PT-2025-38619 · Mapserver+1 · Mapserver+1

Alwin Warringa

·

Published

2025-09-18

·

Updated

2025-10-17

·

CVE-2025-59431

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MapServer versions prior to 8.4.1
Description MapServer, a system for developing web-based GIS applications, contains a flaw in the XML Filter Query directive PropertyName. The PropertyName directive is susceptible to Boolean-based SQL injection due to bypassed expression checking when double quote characters are introduced. This allows manipulation of backend database queries.
Recommendations Update to MapServer version 8.4.1 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-13240
CVE-2025-59431
GHSA-256M-RX4H-R55W

Affected Products

Debian
Mapserver