PT-2026-82485 · Element · Maps-Ng
CVE-2026-66155
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Element maps-ng versions prior to 47.12.3
Element maps-ng versions prior to 48.11.3
Element maps-ng versions prior to 49.16.1
Description
The
si-map component fails to properly neutralize user-controllable input within the points property used to render map pin tooltip labels. This flaw allows an attacker to craft a malicious URL that executes arbitrary script code in the victim's browser session when the victim loads the URL and hovers over a map pin. This is a Cross-Site Scripting (XSS) issue, where malicious scripts are injected into trusted websites.Recommendations
Update Element maps-ng V47 to version 47.12.3 or later.
Update Element maps-ng V48 to version 48.11.3 or later.
Update Element maps-ng V49 to version 49.16.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maps-Ng