Cross Site Scripting Vulnerability in ixmaps Website by ixmaps
CVE-2025-11291
Key Information:
- Vendor
Ixmaps
- Status
- Vendor
- CVE Published:
- 5 October 2025
Badges
What is CVE-2025-11291?
A security flaw exists in the ixmaps website, specifically affecting the HTTP GET Request Handler located in the /map.php file. Manipulation of the 'trid' argument can lead to remote cross site scripting vulnerabilities. Publicly released exploits heighten the risk of this flaw. Continuous delivery practices complicate version tracking, as no specific updates or affected version details have been provided. Despite contacting the vendor regarding this issue, no response was received.
Affected Version(s)
website2017 0c71cffa0162186bc057a76766bc97e9f5a3a2d0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved