Executive brief
MapServer, a platform for building web-based geographic information system (GIS) applications, contains a security flaw in its map-rendering service. An attacker can create a malicious link that, if clicked by a user, executes unauthorized code in that user's web browser. This could allow an attacker to steal session information, impersonate the user, or modify the content of the web page the user is viewing.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in MapServer's Web Map Service (WMS) implementation. The root cause is the improper neutralization of the 'SRS' parameter in WMS 1.3.0 requests when the 'FORMAT' is set to 'application/openlayers'. While WMS 1.1.x correctly validates this parameter, WMS 1.3.0 reflects the unsanitized input directly into the generated OpenLayers HTML template. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted URL, leading to arbitrary JavaScript execution in the context of the victim's browser session. The issue is resolved in MapServer version 8.6.2.
Affected products
- MapServer MapServer 6.0 to 8.6.1
Timeline
- 2026-04-19: patched: Version 8.6.2 released
- 2026-04-19: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: NVD publication date