CVE-2025-59431

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
19/09/2025
Last modified:
08/10/2025

Description

MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database queries. This vulnerability is fixed in 8.4.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osgeo:mapserver:8.4.0:-:*:*:*:*:*:*