{"id":"CVE-2020-15231","aliases":["GHSA-w534-q4xf-h5v2"],"url":"https://o3.security/vulnerability/CVE-2020-15231","summary":"XSS in Mapfish Print relating to JSONP support","details":"### Impact\nA user can use the JSONP support to do a Cross-site scripting.\n\n### Patches\nUse version >= 3.24\n\n### Workarounds\nNo\n\n### References\n* https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e\n* https://cwe.mitre.org/data/definitions/79.html\n\n### For more information\nIf you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397","published":"2020-10-02T20:15:12.567Z","modified":"2026-08-07T15:10:58.299313Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.mapfish.print:print-lib","fixedVersion":"3.24"},{"ecosystem":"Maven","name":"org.mapfish.print:print-servlet","fixedVersion":"3.24"},{"ecosystem":"Maven","name":"org.mapfish.print:print-standalone","fixedVersion":"3.24"}],"fix":{"url":"https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e","label":"mapfish/mapfish-print#1397"},"references":[{"type":"ADVISORY","url":"https://github.com/mapfish/mapfish-print/security/advisories/GHSA-w534-q4xf-h5v2"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/1397/commits/89155f2506b9cee822e15ce60ccae390a1419d5e"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15231"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:10:58.299313Z"}}