DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.
References
Link Resource
https://github.com/domainmod/domainmod/issues/85 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-12-06T03:00:00

Updated: 2018-12-06T03:57:01

Reserved: 2018-12-05T00:00:00


Link: CVE-2018-19892

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-12-06T03:29:00.240

Modified: 2018-12-21T14:54:36.393


Link: CVE-2018-19892

JSON object: View

cve-icon Redhat Information

No data.

CWE