In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mapfish/mapfish-print/security/advisories/GHSA-w534-q4xf-h5v2 | third party advisory |
https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e | third party advisory patch |