CVE-2018-20009
MEDIUM NUCLEIDomainMOD 4.09.03-4.11.01 - Stored Cross-Site Scripting via SSL Provider Name or URL Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-20009. PoCs published by Mohammed Abdul Raheem. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The exploit involves injecting a JavaScript payload into the 'ssl-provider-name' or 'ssl-provider's-url' fields via the /assets/add/ssl-provider.php page.
Description
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The exploit involves injecting a JavaScript payload into the 'ssl-provider-name' or 'ssl-provider's-url' fields via the /assets/add/ssl-provider.php page.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N