CVE-2025-50690 Details
Description
A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to 2025-05-17 (commit 2120adfa17ddd535bd0f539e6c4988fa3a2cb491). The vulnerability is caused by improper handling of user input in the search query parameter. An attacker can craft a specially formed URL with malicious JavaScript code, which is then reflected back and executed in the victim's browser. This flaw allows an attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking, phishing attacks, data theft, or redirection to malicious sites. The issue is exposed on publicly accessible pages, making it exploitable by an unauthenticated attacker.
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in OSGeo SpatialReference.org, affecting versions prior to May 17, 2025. The issue arises from inadequate sanitization of user input in the search query parameter, allowing attackers to inject malicious JavaScript that is executed in the context of the victim's browser. This vulnerability could be exploited to hijack sessions, steal data, or redirect users to harmful websites.
Users are advised to update to the latest version of OSGeo SpatialReference.org, as the vulnerability has been fixed in the version released on May 17, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 13, 2025CISA-ADP
Assessed Aug 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/OSGeo/spatialreference.org | [email protected] | Vendor |
| https://medium.com/@Justinsecure/cracking-open-a-reflected-xss-in-spatialreference-org-fcc42175ae6b | [email protected] | ExploitRemedyTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| OSGeo spatialreference.org | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | New CVE Received | [email protected] |
Volerion