CVE-2018-20011
MEDIUM NUCLEIDomainMOD 4.09.03-4.11.01 - Cross-Site Scripting via Category Name or Stakeholder Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-20011. PoCs published by Mohammed Abdul Raheem. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The exploit involves injecting a JavaScript payload into the 'CategoryName' or 'StakeHolder' fields via the '/assets/add/category.php' page.
Description
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The exploit involves injecting a JavaScript payload into the 'CategoryName' or 'StakeHolder' fields via the '/assets/add/category.php' page.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N