Junglewise Threat Intelligence

CVE-2020-15500: MapTiler TileServer GL reflected XSS in key parameter

CVE-2020-15500 · Severity: low · CVSS 3.1 · Published 2021-05-17

Vendors: npm.

Executive brief

TileServer GL, a server used to distribute vector and raster maps, is vulnerable to a security flaw where malicious scripts can be executed in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal login session information or perform unauthorized actions on the user's behalf within the application. This issue affects the main page of the map server and could impact the reputation and data security of organizations hosting their own map services.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in TileServer GL through version 3.0.0. The root cause is located in `server.js`, where the application fails to sanitize the `key` GET parameter before reflecting it in the HTTP response for the main page. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a JavaScript payload and persuading a victim to visit it. Successful exploitation allows the execution of arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized API interactions. The issue was addressed in version 3.1.0.

Affected products

  • MapTiler TileServer GL <= 3.0.0

Timeline

  • 2020-07-01: disclosed: Issue reported on GitHub and NVD published date
  • 2021-05-17: advisory: GitHub Advisory published
  • 2021-05-11: patched: GitHub review and fix confirmed

References