S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19914 Scanner

CVE-2018-19914 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19914
4.8
CVSS

DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is an open-source web application used to manage domain names, registrars, and DNS records. This software enables users to easily manage their domain names, including registering, transferring, renewing, and managing DNS. With DomainMOD, users can streamline their domain management operations and ensure the accuracy and safety of their domain-related tasks.

However, DomainMOD is not without its vulnerabilities. One of the most significant of these is CVE-2018-19914, which was detected in the software. This vulnerability involves cross-site scripting (XSS) via the assets/add/dns.php Profile Name or notes field. Essentially, by exploiting this vulnerability, an attacker could execute malicious code on a targeted website that uses DomainMOD.

When exploited, CVE-2018-19914 can lead to a range of negative consequences for website owners. For example, attackers may be able to inject malware onto a website, steal sensitive data such as credit card information, login credentials, and other personal data. Moreover, the exploit can lead to a defaced website, which can negatively impact a business' reputation and its ability to attract and retain customers.

In conclusion, DomainMOD's vulnerability to CVE-2018-19914 is a serious concern for website owners who use the software to manage their domain names. To protect against exploits, proper precautions need to be taken. By using the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets and take steps to mitigate risk. Keep your website safe and secure with these tips, and protect yourself against potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Update DomainMOD to the latest version
  • Utilize a web application firewall, which will block malicious attempts to exploit vulnerability
  • Limit access to DomainMOD from external sources
  • Utilize vulnerability scanning software to identify and prevent potential attacks
  • Conduct regular security checks on your website to ensure that there are no vulnerabilities present

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-19914 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD | S4E