S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19752 Scanner

CVE-2018-19752 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19752
4.8
CVSS

DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is a powerful open-source tool that simplifies the process of managing and organizing domain names, web hosts, and other digital assets. Its user-friendly interface and advanced features make it an indispensable asset for website owners, web agencies, and digital marketers. DomainMOD 4.11.01 is the latest stable release of this software, which has been under development for years to cater to the evolving needs of its users.

Unfortunately, DomainMOD 4.11.01 is not immune to security vulnerabilities, and the latest one discovered is CVE-2018-19752, which allows attackers to execute cross-site scripting (XSS) attacks using the notes field for the Registrar, available through assets/add/registrar.php page. The notes field is used to store information related to the Registrar, and its placement in the HTML can be leveraged to inject malicious code into other parts of the website.

When exploited, the vulnerability can lead to serious security breaches, allowing hackers to gain access to sensitive information, steal sensitive data, infect the website with malware or ransomware, or even take complete control of the website. In fact, XSS is ranked the third most common type of web application vulnerability by the Open Web Application Security Project (OWASP), which highlights the severity of this issue.

At s4e.io, we are committed to protecting businesses and individuals from cyber threats. With our advanced vulnerability scanning and management platform, our users can easily and quickly identify vulnerabilities in their digital assets, including DomainMOD, and take appropriate measures to address them before they can be exploited. Our platform offers a suite of pro features that provide comprehensive visibility into security vulnerabilities, as well as advanced analytics and reporting capabilities. Join s4e.io today, and protect your digital assets from the latest security threats!

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against the CVE-2018-19752 vulnerability, including:

  • Keeping DomainMOD up-to-date with the latest patches and security updates
  • Using a Content Security Policy (CSP) to limit the sources of executable scripts, reducing the chances of XSS attacks
  • Using input validation techniques to filter out potentially malicious inputs from the notes field
  • Enforcing strict access controls to limit the privileges of untrusted users
  • Conducting regular vulnerability scans and penetration testing to identify and patch security flaws

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-19752 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD | S4E