Impact
MapServer generates OpenLayers HTML for GetMap requests that reflect the HTTP_X_FORWARDED_HOST header into a single‑quoted JavaScript string without escaping. This flaw allows an attacker to inject malicious JavaScript that will run in a victim’s browser when the victim accesses a crafted URL, enabling theft of session cookies, reading same‑origin data, and performing actions as the user. The weakness is an improper input validation issue, classified as CWE‑79.
Affected Systems
MapServer (MapServer) versions from 6.0 through 8.6.3 are affected. The vulnerability is triggered only when the deployment trusts the X‑Forwarded‑Host header and does not set a fixed ows_onlineresource or MS_ONLINERESOURCE value.
Risk and Exploitability
The CVSS score of 5.3 and an EPSS score of less than 1 % indicate a moderate severity with a low likelihood of exploitation. The likely attack vector is a malicious link or malicious proxy that supplies a crafted X‑Forwarded‑Host header. Based on the description, it is inferred that the attacker can embed single quotes to break out of the JavaScript string and trigger reflected XSS. The vulnerability is not listed in the CISA KEV catalog, but an unauthenticated attacker who can influence the forwarded header can exploit the flaw within the site’s own origin.
OpenCVE Enrichment