CVE-2025-59431: MapServer - WFS XML Filter Query SQL injection
MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database queries. This vulnerability is fixed in 8.4.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59431?
CVE-2025-59431 is classified as a medium severity vulnerability due to the risk of Boolean-based SQL injection.
How do I fix CVE-2025-59431?
The recommended fix for CVE-2025-59431 is to upgrade MapleServer to version 8.4.1 or later.
What impact does CVE-2025-59431 have on my application?
CVE-2025-59431 allows attackers to exploit SQL injection vulnerabilities, potentially leading to unauthorized data access or manipulation.
Which versions of MapServer are affected by CVE-2025-59431?
CVE-2025-59431 affects OSGeo MapServer versions prior to 8.4.1.
Is there a workaround for CVE-2025-59431?
Currently, there is no confirmed workaround for CVE-2025-59431; updating to the latest version is the best mitigation.