Skip to content
Noroxi

DomainMOD records

31 published records for vendor domainmod.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

31 records
  • DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.

    CriticalCVSS 9.8No exploitEPSS 2%

    domainmod · domainmodMar 15, 2021

  • reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

    CriticalCVSS 9.8No exploitEPSS 2%

    domainmod · domainmodMay 8, 2020

  • DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    domainmod · domainmodJul 18, 2019

  • DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    domainmod · domainmodJul 18, 2019

  • domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    domainmod · domainmodJul 18, 2019

  • CVE-2019-9080
    30Monitor

    DomainMOD before 4.14.0 uses MD5 without a salt for password storage.

    HighCVSS 7.5No exploitEPSS 1%

    domainmod · domainmodOct 20, 2020

  • In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.

    MediumCVSS 6.1Proof of conceptEPSS 7%

    domainmod · domainmodAug 29, 2019

  • DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

    MediumCVSS 6.1Proof of conceptEPSS 7%

    domainmod · domainmodNov 9, 2018

  • A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit

    MediumCVSS 6.6No exploitEPSS 0%

    domainmod · domainmodOct 15, 2024

  • DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

    MediumCVSS 6.1Proof of conceptEPSS 3%

    domainmod · domainmodNov 9, 2018

  • DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    domainmod · domainmodMay 24, 2018

  • DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.

    MediumCVSS 5.4Proof of conceptEPSS 2%

    domainmod · domainmodNov 29, 2018

  • DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.

    MediumCVSS 5.4Proof of conceptEPSS 2%

    domainmod · domainmodMay 24, 2018

  • A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitra

    MediumCVSS 5.4Proof of conceptEPSS 1%

    domainmod · domainmodAug 12, 2021

  • DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.

    MediumCVSS 5.4No exploitEPSS 1%

    domainmod · domainmodMay 30, 2018

  • DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.

    MediumCVSS 5.4No exploitEPSS 1%

    domainmod · domainmodMay 30, 2018

  • A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web s

    MediumCVSS 5.4No exploitEPSS 1%

    domainmod · domainmodAug 12, 2021

  • In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected

    MediumCVSS 5.3No exploitEPSS 0%

    domainmod · domainmodOct 15, 2024

  • In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scr

    MediumCVSS 5.3No exploitEPSS 0%

    domainmod · domainmodOct 15, 2024

  • DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

    MediumCVSS 4.8Proof of conceptEPSS 4%

    domainmod · domainmodDec 10, 2018

  • DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

    MediumCVSS 4.8Proof of conceptEPSS 4%

    domainmod · domainmodDec 10, 2018

  • DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

    MediumCVSS 4.8Proof of conceptEPSS 4%

    domainmod · domainmodDec 10, 2018

  • DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

    MediumCVSS 4.8Proof of conceptEPSS 4%

    domainmod · domainmodDec 6, 2018

  • DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

    MediumCVSS 4.8Proof of conceptEPSS 3%

    domainmod · domainmodNov 29, 2018

  • DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

    MediumCVSS 4.8Proof of conceptEPSS 3%

    domainmod · domainmodDec 6, 2018