gist.github.com
https://gist.github.com/SaleSlave/e23d49e7f8eb937784d15c2c2fc34fca CVE-2024-35627
MEDIUMNuclei
TileServer API - Cross Site Scripting
Record summary
CVE-2024-35627 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tileserverglBrowse tileserver / tileserverglDefault status: unknown | CVE List | Before 4.4.10 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMTileServer API - Cross Site ScriptingCVSS 6.1
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.
Impact
Attackers can inject malicious scripts via the key parameter, potentially compromising user sessions or stealing sensitive information.
Remediation
Update tileserver-gl to a version later than v4.4.10 that patches the XSS vulnerability.
WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2024tileserverxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Shodan: http.favicon.hash:-1258058404
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-35627