CVE-2018-19750
MEDIUMDomainMOD < 4.11.01 - Stored Cross-Site Scripting via Custom Domain Field Notes
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19750. PoCs published by Mohammed Abdul Raheem.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The payload is injected into the 'Display Name', 'Description', and 'Notes' fields via the admin panel, triggering when rendered in the browser.
Description
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The payload is injected into the 'Display Name', 'Description', and 'Notes' fields via the admin panel, triggering when rendered in the browser.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N