CVE-2018-19914
MEDIUM NUCLEIDomainMOD 4.09.03-4.11.01 - Stored Cross-Site Scripting via Profile Name or Notes Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19914. PoCs published by Mohammed Abdul Kareem. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The payload is injected into the 'Profile Name' and 'notes' fields via the /assets/add/dns.php page, triggering an alert dialog upon execution.
Description
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The payload is injected into the 'Profile Name' and 'notes' fields via the /assets/add/dns.php page, triggering an alert dialog upon execution.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N