CVE-2020-15500
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 12%
from disclosure to weapon288 days
Published on NVDJul 1
1st PoC+288d
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/49771unverifiedcve_referencepacketstormsecurity.com/files/162193/Tileserver-gl-3.0.0-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.