CVE-2020-15500
Cross-site scripting in TileServer GL
6.1
MEDIUM
CVSS 3.1
EPSS 12.2%
Description
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
How to fix CVE-2020-15500
To remediate CVE-2020-15500, upgrade the affected package to a fixed version below.
- npm/tileserver-gl—upgrade to 3.1.0 or later
Is CVE-2020-15500 being exploited?
Moderate — EPSS is 12.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.1.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |