CVE-2018-19913
MEDIUMDomainMOD < 4.11.01 - Stored Cross-Site Scripting via Registrar Account Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19913. PoCs published by Mohammed Abdul Raheem.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The PoC shows how an attacker can inject malicious JavaScript into the UserName, Reseller ID, and Notes fields via the registrar-accounts.php page.
Description
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The PoC shows how an attacker can inject malicious JavaScript into the UserName, Reseller ID, and Notes fields via the registrar-accounts.php page.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N