Vulnerability Description
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maptiler | Tileserver Php | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/maptiler/tileserver-php/issues/167ExploitIssue Tracking
- https://github.com/mheranco/CVE-2025-44136Exploit
FAQ
What is CVE-2025-44136?
CVE-2025-44136 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthentica...
How severe is CVE-2025-44136?
CVE-2025-44136 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-44136?
Check the references section above for vendor advisories and patch information. Affected products include: Maptiler Tileserver Php.