CVE-2025-59431
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
19/09/2025
Last modified:
08/10/2025
Description
MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database queries. This vulnerability is fixed in 8.4.1.
Impact
Base Score 4.0
8.90
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:osgeo:mapserver:8.4.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



