{"id":"GHSA-g4rw-82hq-8jpr","summary":"MapProxy vulnerable to cross-site scripting in demo service","details":"MapProxy version 1.11.1 and older are vulnerable to cross-site scripting in the demo service resulting in possible information disclosure. An incomplete fix was released in v[1.10.4](https://github.com/mapproxy/mapproxy/issues/322#issuecomment-518573169), and a complete fix was released in v[1.11.1](https://github.com/mapproxy/mapproxy/commit/436c8f489761d1b4ee22b2440b53cc96bbc28aea).","aliases":["CVE-2017-1000426"],"modified":"2025-02-15T05:27:44.144523Z","published":"2022-05-13T01:54:14Z","database_specific":{"severity":"MODERATE","github_reviewed_at":"2023-07-26T20:22:18Z","nvd_published_at":"2018-01-02T21:29:00Z","cwe_ids":["CWE-79"],"github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000426"},{"type":"WEB","url":"https://github.com/mapproxy/mapproxy/issues/322"},{"type":"WEB","url":"https://github.com/mapproxy/mapproxy/commit/420412aad45171e05752007a0a2350c03c28dfd8"},{"type":"WEB","url":"https://github.com/mapproxy/mapproxy/commit/436c8f489761d1b4ee22b2440b53cc96bbc28aea"},{"type":"PACKAGE","url":"https://github.com/mapproxy/mapproxy"}],"affected":[{"package":{"name":"mapproxy","ecosystem":"PyPI","purl":"pkg:pypi/mapproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.1"}]}],"versions":["0.8.0","0.8.0.dev-20100310","0.8.0.dev-20100311","0.8.0.dev-20100315","0.8.0.dev-20100322","0.8.1","0.8.2","0.8.3","0.8.4","0.8.4.1","0.8.5","0.9.0","0.9.0.1","0.9.1","1.0.0","1.0.1","1.1.0","1.1.1","1.1.2","1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.11.0","1.2.0","1.2.1","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.7.1","1.8.0","1.8.1","1.8.2","1.9.0","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g4rw-82hq-8jpr/GHSA-g4rw-82hq-8jpr.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}