DomainMOD records
31 published records for vendor domainmod.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-331 Insufficient Entropy1
- CWE-613 Insufficient Session Expiration1
- CWE-916 Use of Password Hash With Insufficient Computational Effort1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
31 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35358No exploit | DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.domainmod · domainmod · CWE-613 | Critical9.8 | — | 2.4% | Mar 15, 2021 |
40Plan | CVE-2020-12735No exploit | reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.domainmod · domainmod · CWE-331 | Critical9.8 | — | 1.7% | May 8, 2020 |
35Monitor | CVE-2019-1010095No exploit | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).domainmod · domainmod · CWE-352 | High8.8 | — | 0.7% | Jul 18, 2019 |
35Monitor | CVE-2019-1010096No exploit | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).domainmod · domainmod · CWE-352 | High8.8 | — | 0.7% | Jul 18, 2019 |
35Monitor | CVE-2019-1010094No exploit | domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF).domainmod · domainmod · CWE-352 | High8.8 | — | 0.7% | Jul 18, 2019 |
30Monitor | CVE-2019-9080No exploit | DomainMOD before 4.14.0 uses MD5 without a salt for password storage.domainmod · domainmod · CWE-916 | High7.5 | — | 0.7% | Oct 20, 2020 |
26Monitor | CVE-2019-15811Proof of concept | In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.domainmod · domainmod · CWE-79 | Medium6.1 | — | 7.0% | Aug 29, 2019 |
26Monitor | CVE-2018-19136Proof of concept | DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.domainmod · domainmod · CWE-79 | Medium6.1 | — | 6.6% | Nov 9, 2018 |
26Monitor | CVE-2024-48622No exploit | A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/editdomainmod · domainmod · CWE-79 | Medium6.6 | — | 0.3% | Oct 15, 2024 |
25Monitor | CVE-2018-19137Proof of concept | DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.domainmod · domainmod · CWE-79 | Medium6.1 | — | 2.9% | Nov 9, 2018 |
25Monitor | CVE-2018-11404Proof of concept | DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.domainmod · domainmod · CWE-79 | Medium6.1 | — | 2.3% | May 24, 2018 |
22Monitor | CVE-2018-19750Proof of concept | DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.domainmod · domainmod · CWE-79 | Medium5.4 | — | 1.8% | Nov 29, 2018 |
22Monitor | CVE-2018-11403Proof of concept | DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.domainmod · domainmod · CWE-79 | Medium5.4 | — | 1.8% | May 24, 2018 |
21Monitor | CVE-2020-20988Proof of concept | A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitradomainmod · domainmod · CWE-79 | Medium5.4 | — | 1.3% | Aug 12, 2021 |
21Monitor | CVE-2018-11559No exploit | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.domainmod · domainmod · CWE-79 | Medium5.4 | — | 0.7% | May 30, 2018 |
21Monitor | CVE-2018-11558No exploit | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.domainmod · domainmod · CWE-79 | Medium5.4 | — | 0.7% | May 30, 2018 |
21Monitor | CVE-2020-20990No exploit | A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web sdomainmod · domainmod · CWE-79 | Medium5.4 | — | 0.6% | Aug 12, 2021 |
21Monitor | CVE-2024-48623No exploit | In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflecteddomainmod · domainmod · CWE-79 | Medium5.3 | — | 0.2% | Oct 15, 2024 |
21Monitor | CVE-2024-48624No exploit | In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scrdomainmod · domainmod · CWE-79 | Medium5.3 | — | 0.2% | Oct 15, 2024 |
20Monitor | CVE-2018-20009Proof of concept | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.domainmod · domainmod · CWE-79 | Medium4.8 | — | 4.4% | Dec 10, 2018 |
20Monitor | CVE-2018-20010Proof of concept | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.domainmod · domainmod · CWE-79 | Medium4.8 | — | 4.4% | Dec 10, 2018 |
20Monitor | CVE-2018-20011Proof of concept | DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.domainmod · domainmod · CWE-79 | Medium4.8 | — | 4.4% | Dec 10, 2018 |
20Monitor | CVE-2018-19915Proof of concept | DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.domainmod · domainmod · CWE-79 | Medium4.8 | — | 4.0% | Dec 6, 2018 |
20Monitor | CVE-2018-19752Proof of concept | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.domainmod · domainmod · CWE-79 | Medium4.8 | — | 3.3% | Nov 29, 2018 |
20Monitor | CVE-2018-19914Proof of concept | DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.domainmod · domainmod · CWE-79 | Medium4.8 | — | 3.3% | Dec 6, 2018 |
- CVE-2020-3535840Plan
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%domainmod · domainmodMar 15, 2021
- CVE-2020-1273540Plan
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
CriticalCVSS 9.8No exploitEPSS 2%domainmod · domainmodMay 8, 2020
- CVE-2019-101009535Monitor
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).
HighCVSS 8.8No exploitEPSS 1%domainmod · domainmodJul 18, 2019
- CVE-2019-101009635Monitor
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).
HighCVSS 8.8No exploitEPSS 1%domainmod · domainmodJul 18, 2019
- CVE-2019-101009435Monitor
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF).
HighCVSS 8.8No exploitEPSS 1%domainmod · domainmodJul 18, 2019
- CVE-2019-908030Monitor
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
HighCVSS 7.5No exploitEPSS 1%domainmod · domainmodOct 20, 2020
- CVE-2019-1581126Monitor
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
MediumCVSS 6.1Proof of conceptEPSS 7%domainmod · domainmodAug 29, 2019
- CVE-2018-1913626Monitor
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
MediumCVSS 6.1Proof of conceptEPSS 7%domainmod · domainmodNov 9, 2018
- CVE-2024-4862226Monitor
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit
MediumCVSS 6.6No exploitEPSS 0%domainmod · domainmodOct 15, 2024
- CVE-2018-1913725Monitor
DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.
MediumCVSS 6.1Proof of conceptEPSS 3%domainmod · domainmodNov 9, 2018
- CVE-2018-1140425Monitor
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
MediumCVSS 6.1Proof of conceptEPSS 2%domainmod · domainmodMay 24, 2018
- CVE-2018-1975022Monitor
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
MediumCVSS 5.4Proof of conceptEPSS 2%domainmod · domainmodNov 29, 2018
- CVE-2018-1140322Monitor
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
MediumCVSS 5.4Proof of conceptEPSS 2%domainmod · domainmodMay 24, 2018
- CVE-2020-2098821Monitor
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitra
MediumCVSS 5.4Proof of conceptEPSS 1%domainmod · domainmodAug 12, 2021
- CVE-2018-1155921Monitor
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.
MediumCVSS 5.4No exploitEPSS 1%domainmod · domainmodMay 30, 2018
- CVE-2018-1155821Monitor
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
MediumCVSS 5.4No exploitEPSS 1%domainmod · domainmodMay 30, 2018
- CVE-2020-2099021Monitor
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web s
MediumCVSS 5.4No exploitEPSS 1%domainmod · domainmodAug 12, 2021
- CVE-2024-4862321Monitor
In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected
MediumCVSS 5.3No exploitEPSS 0%domainmod · domainmodOct 15, 2024
- CVE-2024-4862421Monitor
In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scr
MediumCVSS 5.3No exploitEPSS 0%domainmod · domainmodOct 15, 2024
- CVE-2018-2000920Monitor
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
MediumCVSS 4.8Proof of conceptEPSS 4%domainmod · domainmodDec 10, 2018
- CVE-2018-2001020Monitor
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
MediumCVSS 4.8Proof of conceptEPSS 4%domainmod · domainmodDec 10, 2018
- CVE-2018-2001120Monitor
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
MediumCVSS 4.8Proof of conceptEPSS 4%domainmod · domainmodDec 10, 2018
- CVE-2018-1991520Monitor
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
MediumCVSS 4.8Proof of conceptEPSS 4%domainmod · domainmodDec 6, 2018
- CVE-2018-1975220Monitor
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
MediumCVSS 4.8Proof of conceptEPSS 3%domainmod · domainmodNov 29, 2018
- CVE-2018-1991420Monitor
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
MediumCVSS 4.8Proof of conceptEPSS 3%domainmod · domainmodDec 6, 2018