MapTiler Tileserver-php v2.0 contains a directory traversal caused by improper sanitization of GET parameters in renderTile function, letting attackers read arbitrary files on the server, exploit requires crafted web requests
id: CVE-2025-44137
info:
name: MapTiler Tileserver-php v2.0 - Unauthenticated File Read
author:
...