packetstormsecurity.com
http://packetstormsecurity.com/files/154270/DomainMod-4.13-Cross-Site-Scripting.html CVE-2019-15811
MEDIUMNuclei
DomainMod 4.13 - Cross-Site Scripting
Record summary
CVE-2019-15811 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBDomainMod 4.13 - Cross-Site ScriptingExploitDB exploitby Damian EbeltiesNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMDomainMOD <=4.13.0 - Cross-Site ScriptingCVSS 6.1
DomainMOD through 4.13.0 contains a cross-site scripting vulnerability via /reporting/domains/cost-by-month.php in Daterange parameters.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Upgrade to the latest version of DomainMOD (>=4.13.1) to mitigate this vulnerability.
WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2019domainmodxssauthenticatededbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:domainmod:domainmod:*:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/47325 https://github.com/domainmod/domainmod/issues/108 https://nvd.nist.gov/vuln/detail/CVE-2019-15811 https://zerodays.lol/ https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4github.com
https://github.com/domainmod/domainmod/issues/108 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15811 zerodays.lol
https://zerodays.lol/