CVE-2025-59431
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2025-59431. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database queries. This vulnerability is fixed in 8.4.1.
Available Exploits
Related News
EU Vulnerability Database
Monitored by ENISA for EU cybersecurity
ENISA Analysis
Malicious code in bioql (PyPI)
Affected Products (ENISA)
ENISA Scoring
CVSS Score (4.0)
EPSS Score
Data provided by ENISA EU Vulnerability Database. Last updated: October 3, 2025