Cross-Site Scripting (XSS) Vulnerability in Trape's trape.js Allows Arbitrary Code Injection

Cross-Site Scripting (XSS) Vulnerability in Trape's trape.js Allows Arbitrary Code Injection

CVE-2019-13488 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter to the /register URI, because the jQuery prepend() method is used.

Learn more about our Web App Pen Testing.