Skip to content
GoogleGHSA-q75m-cx7v-w32h

TrustRatings - Reflected Cross-Site Scripting

MediumPublished Aug 8, 2023

### Summary The /api/v1/widget endpoint of [cust-api.trustratings.com](http://cust-api.trustratings.com/) is vulnerable to a reflected cross-site scripting attack. The value of the hostname passed to the API endpoint is reflected back without any filtering, which allows an attacker to run arbitrary javascript in the victim’s browser. ### Severity Moderate - The endpoint is vulnerable to reflected crosss-site scripting attack which can allow attackers to inject malicious code. ### Proof of Concept As an example, if a victim clicks the following link to the TrustRatings domain, they will get a browser alert demonstrating Javascript execution: ``` https://cust-api.trustratings.com/api/v1/widget/ggc00%22%3e%3cimg%20src%3da%20onerror%3dalert(1)%3esiud8?background=white&orientation=horizontal ``` ### Further Analysis It is recommended TrustRatings perform HTML encoding on any parameters that will be inserted into HTML. ### Timeline **Date reported**: 4/18/2023 **Date fixed**: **Date disclosed**: 8/8/2023

GitHub advisory

Affected versions

PackageAffectedFixed in
/api/v1/widget endpoint of cust-api.trustratings.com
Product
< Nopatchedversionsatthistime.Nopatchedversionsatthistime.
Details and references

More Google advisories

All Google
Advisory
Linux: KVM SEV-ES double fetch vulnerability
MediumSep 6, 2023
Linux Kernel: Ceph file system driver buffer overflow
MediumAug 30, 2023
AMD: Information Leak in Zen 2
High7.1Jul 24, 2023
Linux Kernel: eBPF verifier bug
MediumJun 29, 2023
Harbor: Container Compromise Due to default Credentials
CriticalJun 28, 2023
Connect2id: Timing attack in Nimbus-Jose
MediumJun 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.