{"id":"CVE-2020-15231","aliases":["GHSA-w534-q4xf-h5v2"],"url":"https://o3.security/vulnerability/CVE-2020-15231","summary":"XSS in Mapfish Print relating to JSONP support","details":"In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.","published":"2020-10-02T20:15:12.567Z","modified":"2026-08-07T15:10:58.299313Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.mapfish.print:print-lib","fixedVersion":"3.24"},{"ecosystem":"Maven","name":"org.mapfish.print:print-servlet","fixedVersion":"3.24"},{"ecosystem":"Maven","name":"org.mapfish.print:print-standalone","fixedVersion":"3.24"}],"fix":{"url":"https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e","label":"mapfish/mapfish-print#1397"},"references":[{"type":"ADVISORY","url":"https://github.com/mapfish/mapfish-print/security/advisories/GHSA-w534-q4xf-h5v2"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:10:58.299313Z"}}