7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
CVE-2026-4060 — Geo Mashup ≤ 1.13.18 Unauthenticated SQL Injection PoC -blue Unauthenticated attackers can inject arbitrary SQL into the ORDER BY clause via the sort parameter of the Geo Mashup render-map endpoint, enabling time-based blind extraction...
Basic Information
ID
EBC57F95-FCBC-5E72-B5F4-3C5722E51463
Published
May 14, 2026 at 02:10
Modified
May 14, 2026 at 03:14