Executive brief
Siemens Element maps-ng is a mapping library used in web applications to display interactive maps with clickable pins. A cross-site scripting vulnerability in the tooltip component allows attackers to craft malicious URLs that, when clicked and hovered over, execute arbitrary JavaScript code in a user's browser, potentially leading to account compromise, data theft, or session hijacking.
Technical details
The si-map component fails to properly sanitize user-controlled input in the points property, which is used to render tooltip labels for map pins. This is a classic cross-site scripting (XSS) vulnerability (CWE-79). An authenticated attacker can craft a malicious URL containing JavaScript payload; when a victim loads the URL and hovers over a map pin, the unescaped script executes in the victim's browser session with full access to the application context. The vulnerability requires user interaction (hovering over a pin) and prior authentication, but can affect all users who interact with a compromised map instance. Patches are available: Element maps-ng V47.12.3+, V48.11.3+, and V49.16.1+.
Affected products
- Siemens Element maps-ng V47 All versions < V47.12.3
- Siemens Element maps-ng V48 All versions < V48.11.3
- Siemens Element maps-ng V49 All versions < V49.16.1
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Updates available: V47.12.3, V48.11.3, V49.16.1