Reflected XSS Vulnerability in TileServer GL

Reflected XSS Vulnerability in TileServer GL

CVE-2020-15500 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

Learn more about our Cis Benchmark Audit For Server Software.