Skip to content

CVE-2025-11291: Reflected Cross-Site-Scripting (XSS) in IXMaps.ca  #2

@PlsRevert

Description

@PlsRevert

Affected software: (Code)
https://github.com/ixmaps/website2017

Affected software: (Actual live URL)
https://www.ixmaps.ca/

Issue:
A reflected cross-site scripting (XSS) vulnerability exists in the site at https://www.ixmaps.ca/ that enables a remote attacker to execute arbitrary JavaScript code in the user's browser.

Steps to Reproduce:
Visit https://www.ixmaps.ca/, and send the payload shown below in the 'trid' parameter.

Image

Notice that the payload has been reflected in the response.

Image

Alternative payload to send in 'trid' parameter:
%3cscript%3ealert('456')%3c%2fscript%3enp9ly%3cscript%3ealert(1)%3c%2fscript%3egrkmm

Vulnerable Portion of Code:

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions