CVE-2025-44137 | MapTiler Tileserver-php 2.0 GET Parameter tileserver.php renderTile TileMatrix/TileRow/TileCol/Format path traversal (Issue 167)
A vulnerability was found in MapTiler Tileserver-php 2.0. It has been rated as critical. This issue affects the function renderTile of the file tileserver.php of the component GET Parameter Handler. The manipulation of the argument TileMatrix/TileRow/TileCol/Format leads to path traversal.
The identification of this vulnerability is CVE-2025-44137. The attack may be initiated remotely. There is no exploit available.