You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Issue:
A reflected cross-site scripting (XSS) vulnerability exists in the site at https://www.ixmaps.ca/ that enables a remote attacker to execute arbitrary JavaScript code in the user's browser.
Steps to Reproduce:
Visit https://www.ixmaps.ca/, and send the payload shown below in the 'trid' parameter.
Notice that the payload has been reflected in the response.
Alternative payload to send in 'trid' parameter:
%3cscript%3ealert('456')%3c%2fscript%3enp9ly%3cscript%3ealert(1)%3c%2fscript%3egrkmm